Linux Kernel Privilege Escalation Vulnerability

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.

Published 31 Aug 2026Updated 31 Aug 202622 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.

Affected versions

Kernel: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · briskets/CVE-2021-3493Ubuntu OverlayFS Local Privesc★ 443briskets2021-04-19CandidatePoC-in-GitHub · oneoy/CVE-2021-3493★ 3oneoy2021-04-22CandidatePoC-in-GitHub · Abdennour-py/CVE-2021-3493★ 0Abdennour-py2021-05-02CandidatePoC-in-GitHub · inspiringz/CVE-2021-3493CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)★ 42inspiringz2021-07-07CandidatePoC-in-GitHub · derek-turing/CVE-2021-3493CVE-2021-3493 Ubuntu漏洞★ 0derek-turing2021-07-16CandidatePoC-in-GitHub · cerodah/overlayFS-CVE-2021-34932021 kernel vulnerability in Ubuntu.★ 1cerodah2021-09-12CandidatePoC-in-GitHub · puckiestyle/CVE-2021-3493★ 2puckiestyle2021-10-02CandidatePoC-in-GitHub · fei9747/CVE-2021-3493★ 1fei97472022-11-29CandidatePoC-in-GitHub · pmihsan/OverlayFS-CVE-2021-3493Exploit For OverlayFS★ 0pmihsan2023-01-16CandidatePoC-in-GitHub · ptkhai15/OverlayFS---CVE-2021-3493★ 0ptkhai152023-08-25CandidatePoC-in-GitHub · iamz24/CVE-2021-3493_CVE-2022-3357★ 0iamz242024-07-04CandidatePoC-in-GitHub · fathallah17/OverlayFS-CVE-2021-3493Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!★ 0fathallah172024-09-16CandidatePoC-in-GitHub · Sornphut/OverlayFS---CVE-2021-3493★ 0Sornphut2025-03-05CandidatePoC-in-GitHub · cyberx-1/OverlayFS-CVE-2021-3493root Privileges★ 0cyberx-12025-10-22CandidatePoC-in-GitHub · George-Yanni/DeepRootCVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.★ 0George-Yanni2025-12-23CandidatePoC-in-GitHub · iqbalhussainas/OverlayFS-LPE-ExploitType Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab★ 0iqbalhussainas2026-04-20CandidatePoC-in-GitHub · Ayham-Megdadi/Zero-Day-LegacyA vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hijacking, SSH access, password cracking, privilege escalation via CVE-2021-3493, and full root compromise. Developed as a graduation project at Ajloun National University (ANU), awarded 97%.★ 2Ayham-Megdadi2026-07-05CandidatePoC-in-GitHub · WhatsWrongAndWhy/CVE-2021-3493★ 0WhatsWrongAndWhy2026-07-21CandidatePoC-in-GitHub · 0xlane/CVE-2021-3493★ 00xlane2026-07-23CandidatePoC-in-GitHub · r3dw4n48m3d/CVE-2021-3493-ExploitIt's a CVE-2021-3493 Exploit written in C★ 0r3dw4n48m3d2026-09-01Candidate