CVE-2021-3493 is a privilege-escalation vulnerability in the Linux kernel OverlayFS implementation as shipped with an Ubuntu-specific patch permitting unprivileged OverlayFS mounts. OverlayFS did not correctly validate the setting of file capabilities on files in an underlying filesystem with respect to user namespaces. An attacker can abuse unprivileged user namespaces and unprivileged overlay mounts to set file capabilities improperly and obtain elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
15 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a small standalone C proof-of-concept repository for CVE-2021-3493, not a framework module. It contains README.md and exploit.c; the README identifies affected Ubuntu releases and supplies a gcc compilation command. The exploit is a local Linux privilege-escalation program targeting OverlayFS incorrect validation of security.capability extended attributes. It first removes and recreates a relative ./ovlcap workspace, creates lower/upper/work/merge directories, enters new mount and user namespaces, configures UID/GID mappings, and mounts OverlayFS. It copies its own executable from /proc/self/exe into the merged layer as magic, assigns a crafted all-capabilities security.capability xattr, waits for the setup child process to exit, and executes the resulting upper-layer file. The re-executed magic instance invokes setuid(0) and setgid(0), then starts /bin/bash interactively with user startup files disabled. The rm -rf operation is limited to the fixed relative ./ovlcap directory and is setup cleanup rather than evidence of a fake exploit. No network, HTTP, DNS, or remote command-and-control endpoints are present.
This repository is a compact local privilege-escalation PoC for CVE-2021-3493 affecting Ubuntu-specific OverlayFS behavior in vulnerable kernels. It contains 5 files: a Makefile, README, and two C programs forming a two-stage exploit. The main exploit logic is in exploit.c, which creates a staging tree under /tmp/.ovlcap, forks, unshares into new mount and user namespaces, writes /proc/self/{setgroups,uid_map,gid_map}, mounts an overlay filesystem, copies a companion payload binary into the overlay merge directory, and sets a crafted security.capability xattr granting all permitted/effective capabilities. After the child exits, the parent executes the resulting file from /tmp/.ovlcap/upper/rootshell in the init namespace. The second stage, rootshell.c, demonstrates the gained capabilities by printing capability fields from /proc/self/status, calling setuid(0) and setgid(0), then either executing a user-supplied command or spawning /bin/bash -p as a real root shell. The exploit is clearly functional rather than merely demonstrative: it includes a working payload and cleanup/build instructions. There are no network endpoints or remote targets; the attack vector is strictly local. The README thoroughly documents affected Ubuntu versions, prerequisites, rationale for using /tmp instead of /dev/shm, and the two-stage design improvement over the original PoC.
This repository is a small standalone local privilege escalation exploit for CVE-2021-3493 affecting vulnerable Ubuntu Linux kernels. It contains two files: a README describing the OverlayFS LPE scenario and a single C source file, exploit.c, which implements the exploit logic. The exploit is clearly functional rather than a detector. It stages an OverlayFS directory structure under ./ovlcap, removes any prior copy with rm -rf, creates work/lower/upper/merge directories, and then unshares into new mount and user namespaces. It writes to /proc/self/setgroups, /proc/self/uid_map, and /proc/self/gid_map to establish namespace mappings for the current unprivileged user. It then mounts an overlay filesystem at ./ovlcap/merge using lowerdir, upperdir, and workdir parameters. After mounting, the program copies its own executable from /proc/self/exe to ./ovlcap/merge/magic and sets the security.capability extended attribute on that file with a hardcoded capability blob intended to grant elevated privileges. Because of the OverlayFS vulnerability, the modified file becomes available in ./ovlcap/upper/magic with capabilities preserved in a way that can be abused. The parent process waits for the child to finish setup, then executes ./ovlcap/upper/magic with argument shell. When the binary detects it is invoked as magic or with the shell argument, it calls setuid(0) and setgid(0) and spawns /bin/bash --norc --noprofile -i, yielding an interactive root shell. There are no network indicators, remote callbacks, or C2-style endpoints. All observables are local filesystem and procfs paths. The exploit’s main capability is straightforward local root escalation on a vulnerable host. Because the payload is hardcoded to spawn a root bash shell and is not framework-driven or highly customizable, the maturity is best classified as OPERATIONAL.
Repository contains a small, self-contained local privilege escalation PoC for CVE-2021-3493 (Ubuntu-specific OverlayFS/user-namespace file capabilities bug). Structure: - README.md: Describes CVE-2021-3493, affected Ubuntu versions, build/run instructions, and links to Ubuntu advisory. - kernel_exploit.c: C exploit implementing the LPE. Exploit flow (kernel_exploit.c): 1) Prepares a workspace under ./ovlcap (work/lower/upper/merge) and deletes any prior state via `rm -rf ./ovlcap/`. 2) Calls `unshare(CLONE_NEWNS | CLONE_NEWUSER)` to create new mount and user namespaces. 3) Writes to /proc/self/setgroups, /proc/self/uid_map, /proc/self/gid_map to map the current user/group to namespace root (uid/gid 0). 4) Mounts an OverlayFS instance at ./ovlcap/merge with lowerdir/upperdir/workdir under ./ovlcap. 5) Copies its own executable (/proc/self/exe) to ./ovlcap/merge/magic and sets the xattr `security.capability` to a blob representing “all capabilities effective+permitted” (all+ep). 6) After the child finishes, the parent executes ./ovlcap/upper/magic with argument "shell". Due to the vulnerability, the capability xattr improperly applies such that the executed file gains elevated privileges. 7) The "magic" execution path calls setuid(0)/setgid(0) and execs /bin/bash interactively. Primary capability: local root shell via OverlayFS + file capabilities abuse. No network communication is present; all observable targets are local filesystem paths, procfs namespace mapping files, and the OverlayFS mount operation.
This repository is a comprehensive local privilege escalation and post-exploitation toolkit targeting CVE-2021-3493 (OverlayFS vulnerability) on Linux systems. The main exploit is implemented in a single C source file (comprehensive.c), which, when compiled and executed on a vulnerable system, escalates privileges to root by abusing OverlayFS capability handling. After successful exploitation, the tool presents a menu-driven interface offering a wide range of post-exploitation modules: - SSH backdoor key injection for persistent root access - Sudoers modification for passwordless sudo - Cron job and systemd service installation for persistence (including reverse shell capability) - LD_PRELOAD shared library backdoor for system-wide code injection - System information collection, credential search, and lateral movement checks - C2 connectivity simulation (network checks, not actual C2) - Root shell spawn and cleanup options Each module is documented in its own README, providing detailed operational guidance. The exploit is operational and provides real, persistent access and post-exploitation capabilities, but is not part of a larger framework. The attack vector is local (requires code execution on the target). Numerous fingerprintable endpoints are used, including system files for persistence and credential harvesting. The code is mature, modular, and suitable for red team or penetration testing use.
This repository contains a single C exploit (Exploit.c) and a minimal README. The exploit targets the Linux kernel's overlayfs and user namespace features to escalate privileges from an unprivileged user to root. The code creates several directories for overlayfs, sets up a new user and mount namespace, manipulates /proc/self/uid_map and /proc/self/gid_map to map the current user to root, mounts an overlay filesystem, and copies itself into the overlay with manipulated capabilities. The final payload is a copy of the exploit binary with elevated capabilities, which is then executed to spawn a root shell (/bin/bash) as UID 0. The exploit is local-only and does not interact with network endpoints. The README simply provides compilation instructions and demonstrates the expected result (root shell). The exploit is operational and provides a working privilege escalation payload for vulnerable Linux systems.
This repository is a comprehensive penetration testing report and toolkit for Ubuntu Touch (v16.04, Kernel 5.4.0), focusing on several critical and high-severity vulnerabilities. The main exploit capability is a local privilege escalation proof-of-concept (PoC) for CVE-2021-3493, targeting the Linux kernel's OverlayFS implementation. The PoC, implemented in C (scripts/CVE-2021-3493-poc.c), creates a crafted overlay filesystem and exploits improper capability handling to escalate privileges and spawn a root shell. The payload is a bash script that, when executed, provides root access and displays system/user information. The repository also includes detailed markdown reports for other vulnerabilities (e.g., insecure credential storage, disabled ASLR, weak snap confinement, outdated packages, unencrypted storage, and unrestricted sudo access), each with technical details, proof-of-concept commands, and remediation steps. The MobSF setup script (scripts/mobsf_setup.sh) automates the installation and configuration of the Mobile Security Framework for further application security testing on Ubuntu Touch. Fingerprintable endpoints include several temporary file paths used by the exploit (/tmp/lower, /tmp/upper, /tmp/work, /tmp/overlay), system configuration files (/etc/NetworkManager/system-connections/*, /etc/sudoers), and user data directories (/home/phablet/.local/share/). The attack vector for the main exploit is local, requiring shell access to the target device. The repository is structured for both reporting and exploitation, providing actionable resources for developers and security testers.
This repository contains a single Metasploit module (modules/exploits/linux/local/cve_2021_3493_overlayfs.rb) that exploits CVE-2021-3493, a local privilege escalation vulnerability in Ubuntu's implementation of overlayfs. The exploit targets Ubuntu systems with kernel versions between 3.13 and 5.14, where unprivileged user namespaces are enabled. The module checks for the appropriate architecture (x86_64 or aarch64) and kernel version, uploads and compiles (or drops a precompiled) exploit binary, and then uploads a Metasploit payload (such as a shell or meterpreter). The exploit is executed, and if successful, the payload is run as root, granting the attacker elevated privileges. The module cleans up after execution by removing the exploit directory. The only fingerprintable endpoint is the writable directory used for file drops (default: /tmp). This is a weaponized, fully operational exploit module integrated into the Metasploit framework.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting Ubuntu systems with a vulnerable OverlayFS implementation. The exploit is implemented in C (exploit.c) and is accompanied by a README.md that explains the vulnerability and affected versions, and a command.md with build/run instructions. The exploit works by creating a set of directories for OverlayFS, setting up a user namespace, and mounting an overlay filesystem. It then manipulates file capabilities on a copied binary to grant it elevated privileges, exploiting the lack of proper capability checks in the vulnerable OverlayFS implementation. Finally, it executes the manipulated binary to spawn a root shell. The exploit is operational and provides a working local root shell on affected systems. All operations are local, and the exploit does not require network access. The main fingerprintable endpoints are the file paths used for the OverlayFS setup and the manipulated binary.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting Ubuntu systems with a vulnerable OverlayFS implementation. The exploit is written in C and consists of a single code file (exploit.c) and a README.md with usage instructions and background information. The exploit works by creating a set of directories for overlayfs, setting up a user namespace, and mounting an overlay filesystem in a way that allows the attacker to set file capabilities on a copy of the exploit binary. This binary is then executed with elevated privileges, ultimately spawning a root shell (/bin/bash). The exploit requires local access to the target system and is effective against several Ubuntu versions prior to the fix in Linux kernel 5.11. The repository is operational and provides a working privilege escalation payload.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting the Linux kernel's overlayfs implementation. The exploit is implemented in a single C file (exploit.c) and is accompanied by a minimal README. The exploit works by creating a set of directories for overlayfs, setting up a new user and mount namespace, and manipulating file capabilities on a copy of itself within the overlayfs mount. It then executes this binary to spawn a root shell (/bin/bash). The exploit interacts with several fingerprintable file system endpoints, including /proc/self/setgroups, /proc/self/uid_map, /proc/self/gid_map, and various directories under ./ovlcap. The exploit is operational and provides a working root shell on vulnerable systems. The repository is straightforward, with the main logic contained in exploit.c and no extraneous files.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting Ubuntu systems with a vulnerable OverlayFS implementation. The exploit is implemented in C (exploit.c) and is accompanied by a README.md that provides background, usage instructions, and references. The exploit works by creating a set of directories for OverlayFS, setting up a user namespace, and mounting an overlay filesystem. It then copies its own binary into the overlay, sets special file capabilities, and finally executes the payload as root, resulting in a root shell (/bin/bash). The exploit interacts with several fingerprintable file system paths, including /proc/self/* files for namespace manipulation and various directories under ./ovlcap for the overlay operation. The exploit is operational and provides a working root shell if run on a vulnerable system. No network endpoints are involved; the attack vector is purely local.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting Ubuntu systems (versions 14.04 ESM through 20.10) with a vulnerable OverlayFS implementation in the Linux kernel. The exploit is implemented in C (exploit.c) and is accompanied by a README.md with usage instructions and background information. The exploit works by creating a set of directories for OverlayFS, setting up a user namespace, and mounting OverlayFS in a way that allows the attacker to set file capabilities on a copy of the exploit binary. This manipulated binary is then executed to spawn a root shell (/bin/bash). The exploit requires local access to the target system and does not involve any network communication. All operations are performed on local file system paths, primarily within a temporary directory (./ovlcap). The exploit is operational and provides a working root shell if successful.
This repository contains a local privilege escalation exploit for the OverlayFS vulnerability (CVE-2021-3493) affecting certain versions of Ubuntu Linux. The exploit is implemented in C (exploit.c) and is accompanied by a README.md that explains the vulnerability and usage. The exploit works by creating a set of directories for OverlayFS, setting up a user namespace, and mounting an overlay filesystem. It then copies its own binary into the merged directory, sets special capabilities on it, and finally executes it to spawn a root shell (/bin/bash). The exploit requires the attacker to be able to execute binaries on the target system. The repository is structured simply, with the main exploit logic in a single C file and documentation in the README. No network endpoints are involved; all operations are local file and process manipulations.
This repository contains a local privilege escalation exploit for CVE-2021-3493, targeting Ubuntu systems with a vulnerable overlayfs implementation. The exploit is implemented in C (exploit.c) and is accompanied by a README.md that describes the vulnerability, affected versions, and usage instructions. The exploit works by creating a set of directories in /dev/shm/.ovlcap, setting up a user namespace, and mounting an overlayfs filesystem. It then copies its own executable into the overlay mount, sets special capabilities using setxattr, and finally executes a shell or arbitrary command as root. The exploit requires local access to the target system and does not involve any network endpoints. The main fingerprintable endpoints are the temporary directories and files created in /dev/shm/.ovlcap and the manipulation of /proc/self/* files for namespace and capability setup. The exploit is operational and provides a working local privilege escalation on affected Ubuntu systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.