⚠ Actively exploited
Added to CISA KEV on 2022-10-20. Federal agencies required to patch by 2022-11-10. Required action: Apply updates per vendor instructions..
Severity
7.8HIGHNVD
CNA8.8VulnCheck8.8
EPSS
76.4%
top 1.06%
CISA KEV
KEV
Added 2022-10-20
Due 2022-11-10
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 17
KEV addedOct 20
KEV dueNov 10
CISA Required Action: Apply updates per vendor instructions.

Description

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5ubuntu/linux_kernel5.8 kernel5.8.0-50.56+3
Debianlinux/linux_kernel< 5.10.38-1+3
Ubuntulinux/linux_kernel< 4.4.0-210.242+5
NVDcanonical/ubuntu_linux18.04.120.04+2

Patches

🔴Vulnerability Details

9
GHSA
GHSA-2fj2-4h38-3c72: The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i2022-05-24
OSV
Kernel Live Patch Security Notice2021-05-03
OSV
linux, linux-aws, linux-gke-5.3, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem-5.6, linux-raspi2, linux-raspi2-5.3, linux-snapdragon regression2021-04-22
OSV
CVE-2021-3493: The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i2021-04-17
CVEList
CVE-2021-3493: The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i2021-04-17

💥Exploits & PoCs

1
Metasploit
GameOver(lay) Privilege Escalation and Container Escape

📋Vendor Advisories

8
CISA
Linux Kernel Privilege Escalation Vulnerability2022-10-20
Ubuntu
Kernel Live Patch Security Notice2021-05-03
Ubuntu
Linux kernel regression2021-04-22
Red Hat
kernel: overlayfs file system caps privilege escalation2021-04-16
Ubuntu
Linux kernel (OEM) vulnerabilities2021-04-15
CVE-2021-3493 — Privilege Context Switching Error | cvebase