SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-3493

Linux Kernel Privilege Escalation Vulnerability

KEVHIGH 7.8EPSS 49.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 November 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
49.17% probability · 99th percentile
CISA KEV
Listed 20 October 2022 · due 10 November 2022
Weakness
CWE-270, CWE-863
Affected
canonical/ubuntu linux
Source
security@ubuntu.com

CISA notes

Apply updates per vendor instructions. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7c03e2cda4a584cadc398e8f6641ca9988a39d52; https://nvd.nist.gov/vuln/detail/CVE-2021-3493

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.