CVE-2021-3847

Related Vulnerabilities: CVE-2021-3847  

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

Description

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

Mitigation

The mitigation is to mount overlayfs with nosuid if lower layer is nosuid.

Additional Information

  • Bugzilla 2009704: CVE-2021-3847 kernel: low-privileged user privileges escalation
  • CWE-281: Improper Preservation of Permissions
  • FAQ: Frequently asked questions about CVE-2021-3847