Improper Privilege Management Affecting torvalds/linux package, versions [,v5.11-rc1)
Threat Intelligence
Exploit Maturity
Mature
EPSS
0.83% (83rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-TORVALDSLINUX-7644402
- published 7 Aug 2024
- disclosed 6 Aug 2024
Introduced: 6 Aug 2024
CVE-2021-3493 Open this link in a new tabHow to fix?
Upgrade torvalds/linux
to version v5.11-rc1 or higher.
Overview
Affected versions of this package are vulnerable to Improper Privilege Management due to improper validation in the overlayfs
implementation with respect to user namespaces. An attacker can gain elevated privileges by exploiting the setting of file capabilities on files in an underlying file system. This is only exploitable if the system has the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts