CVE-2021-33909 ("Sequoia") is a local privilege-escalation flaw in the Linux kernel filesystem layer, caused by converting a size_t buffer length to a signed 32-bit integer. An unprivileged local user can build and mount a directory hierarchy whose path exceeds 1 GB, then read /proc/self/mountinfo to trigger a predictable 10-byte out-of-bounds write containing //deleted relative to a vmalloc buffer. Qualys demonstrated root compromise on default Ubuntu 20.04–21.04, Debian 11, and Fedora 34 Workstation systems.
The vulnerability, introduced in Linux 3.16, can be exploited by corrupting a validated eBPF program and overwriting the kernel modprobe_path. Linux commit 8cae8cd89f05f6de223d63e6d15e31c8ba9cf53b mitigates the allocation issue by rejecting seq_file buffer requests larger than MAX_RW_COUNT before kvmalloc. Organizations should deploy kernel updates; disabling unprivileged user namespaces and unprivileged BPF can reduce exposure to the demonstrated exploit chain but does not remove the underlying defect.

Get the actors, campaigns, and ATT&CK mapping behind it.
33 events from the most recent confirmed update back to the earliest known activity.
Qualys published an advisory for local information disclosure in apport and systemd-coredump, tracked as CVE-2025-5054 and CVE-2025-4598.
Qualys published an advisory covering three bypasses of Ubuntu's unprivileged user namespace restrictions.
Qualys published an advisory for a man-in-the-middle attack against OpenSSH clients with VerifyHostKeyDNS enabled, tracked as CVE-2025-26465.
Qualys published an advisory for a denial-of-service attack affecting OpenSSH client and server, tracked as CVE-2025-26466.
Qualys published an advisory for local privilege escalations in needrestart, tracked as CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-10224, and CVE-2024-11003.
Qualys published regreSSHion, an advisory for remote code execution in OpenSSH server on glibc-based Linux systems, tracked as CVE-2024-6387.
Qualys published an advisory showing that nontransitive comparison functions can cause out-of-bounds reads and writes in glibc qsort().
Qualys published an advisory for a heap-based buffer overflow in glibc syslog(), tracked as CVE-2023-6246.
Qualys published the Looney Tunables advisory for local privilege escalation in glibc ld.so, tracked as CVE-2023-4911.
Qualys published an advisory for remote code execution in OpenSSH's forwarded ssh-agent, tracked as CVE-2023-38408.
Qualys published an advisory for local privilege escalation and remote code execution vulnerabilities in RenderDoc, tracked as CVE-2023-33863, CVE-2023-33864, and CVE-2023-33865.
Qualys published an advisory for a race condition in snap-confine's must_mkdir_and_open_with_perms(), tracked as CVE-2022-3328.
Qualys published the Leeloo Multipath advisory for an authorization bypass and symlink attack in multipathd, tracked as CVE-2022-41974 and CVE-2022-41973.
Qualys published Oh Snap! More Lemmings, an advisory for local privilege escalation in snap-confine, tracked as CVE-2021-44731.
Qualys published the pwnkit advisory for a local privilege escalation in polkit's pkexec, tracked as CVE-2021-4034.
Qualys published an advisory for denial of service through stack exhaustion in systemd PID 1, tracked as CVE-2021-33910.
Qualys released CVE-2021-33909, dubbed Sequoia, a Linux filesystem-layer size_t-to-int flaw that it demonstrated could yield root access on default installations of several Linux distributions.
Eric Sandeen authored a patch to reject seq_file buffer requests exceeding MAX_RW_COUNT, addressing the large-allocation behavior associated with the Qualys-reported issue.
Qualys reported CVE-2021-33909 (Sequoia) and the related systemd flaw CVE-2021-33910 to Red Hat Product Security.
Qualys published 21Nails, an advisory covering multiple vulnerabilities in Exim Mail Server.
Qualys published the Baron Samedit advisory for a heap-based buffer overflow in Sudo, tracked as CVE-2021-3156.
Qualys published an advisory describing remote code execution in qmail, tracked as CVE-2005-1513.
Qualys published advisories covering local privilege escalation, remote code execution, and local information disclosure in OpenSMTPD, tracked as CVE-2020-8794 and CVE-2020-8793.
Qualys published an advisory for local privilege escalation and remote code execution in OpenSMTPD, tracked as CVE-2020-7247.
Qualys published The Return of the WIZard advisory for remote code execution in Exim, tracked as CVE-2019-10149.
Qualys published the System Down advisory describing a systemd-journald exploit.
Qualys published the Mutagen Astronomy advisory for an integer overflow in Linux create_elf_tables(), tracked as CVE-2018-14634.
Qualys published its Stack Clash advisory.
Qualys published an advisory covering OpenSSH vulnerabilities tracked as CVE-2016-0777 and CVE-2016-0778.
Qualys published the GHOST advisory for a glibc gethostbyname buffer overflow, tracked as CVE-2015-0235.
Linux commit 058504ed introduced the seq_file vmalloc fallback that later underpinned CVE-2021-33909 (Sequoia).
Linus Torvalds committed Linux patch 8cae8cd89f05f6de223d63e6d15e31c8ba9cf53b, adding a MAX_RW_COUNT limit before seq_file allocations and marking it for stable-kernel consideration.
Red Hat Product Security-developed patches for CVE-2021-33909 and CVE-2021-33910 were distributed to the linux-distros mailing list.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
git.kernel.org
Open sourceopenwall.com
Open sourcegoogleprojectzero.blogspot.com
Open sourcegoogleprojectzero.blogspot.com
Open sourcequalys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.