October 20, 2022 · Applied Cybernetics Group
CVE-2021-3493 — Linux Kernel
Linux Kernel Privilege Escalation Vulnerability
- Added to KEV
2022-10-20- Federal due date
2022-11-10- Vendor
- Linux
- Product
- Kernel
- EPSS
- 99.1th percentile (score 0.800, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-3493
CISA short description
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
Required action
Apply updates per vendor instructions.