CVE-2021-3493
Linux Kernel Privilege Escalation Vulnerability
CVSS
—
No CVSS
EPSS
49.2%
p99
KEV
YES
Oct 20, 2022
Exploit Today
80
0-100
Published: — · Last modified: —
49.2%EPSS · 30 days49.2%
2026-08-022026-08-31
Product
Linux / Kernel
Vulnerability
Linux Kernel Privilege Escalation Vulnerability
Added to KEV
Oct 20, 2022
Remediate by
Nov 10, 2022
Known ransomware use
No
Summary description
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
Required action
Apply updates per vendor instructions.
Notes
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7c03e2cda4a584cadc398e8f6641ca9988a39d52; https://nvd.nist.gov/vuln/detail/CVE-2021-3493
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-533627.8 HIG41.5%
KEV—62Linux Kernel Unspecified Vulnerability3dCVE-2026-314317.8 HIG100.0%
KEV—80Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability34dCVE-2025-383527.8 HIG68.0%
KEV—70Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability32dCVE-2024-10867.8 HIG98.0%
KEV—79Linux Kernel Use-After-Free Vulnerability24dCVE-2022-25865.3 MED95.4%
KEV—79Linux Kernel Use-After-Free Vulnerability11dCVE-2022-09957.8 HIG95.1%
KEV—79Linux Kernel Out-of-Bounds Write Vulnerability4d