Rapid7 Vulnerability & Exploit Database

2021 Ubuntu Overlayfs LPE

Back to Search

2021 Ubuntu Overlayfs LPE



This module exploits a vulnerability in Ubuntu's implementation of overlayfs. The vulnerability is the result of failing to verify the ability of a user to set the attributes in a running executable. Specifically, when Overlayfs sends the set attributes data to the underlying file system via `vfs_setxattr`, it fails to first verify the data by calling `cap_convert_nscap`. This vulnerability was patched by moving the call to `cap_convert_nscap` into the `vfs_setxattr` function that sets the attribute, forcing verification every time the `vfs_setxattr` is called rather than trusting the data was already verified.


  • ssd-disclosure
  • bwatters-r7




Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use exploit/linux/local/cve_2021_3493_overlayfs
msf exploit(cve_2021_3493_overlayfs) > show targets
msf exploit(cve_2021_3493_overlayfs) > set TARGET < target-id >
msf exploit(cve_2021_3493_overlayfs) > show options
    ...show and set options...
msf exploit(cve_2021_3493_overlayfs) > exploit

Time is precious, so I don’t want to do something manually that I can automate. Leveraging the Metasploit Framework when automating any task keeps us from having to re-create the wheel as we can use the existing libraries and focus our efforts where it matters.

– Jim O’Gorman | President, Offensive Security