In addition to Weibo, there is also WeChat
Please pay attention

WeChat public account
Shulou
2025-10-24 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >
Share
Shulou(Shulou.com)05/31 Report--
How to carry out Ubuntu vulnerability CVE-2021-3493 early warning, I believe that many inexperienced people do not know what to do. Therefore, this paper summarizes the causes and solutions of the problem. Through this article, I hope you can solve this problem.
one。 Brief introduction of CVE-2021-3493
The OverlayFS vulnerability allows local users under Ubuntu to gain root privileges. A Ubuntu-specific problem in the overlayfs file system in the Linux kernel, in which it does not properly validate the application about the file system functionality of the user namespace. Because Ubuntu comes with a patch that allows unprivileged overlayfs mounts, local attackers can use it to gain higher privileges.
At present, the details of the vulnerability have been made public, please take measures to protect the affected users as soon as possible.
two。 Affect the version
Ubuntu 20.10
Ubuntu 20.04 LTS
Ubuntu 18.04 LTS
Ubuntu 16.04 LTS
Ubuntu 14.04 ESM
three。 Loophole analysis
Linux supports file functions stored in extended file attributes that work like setuid-bit, but with finer granularity. The simplified process for setting up the file function in pseudo code is as follows:
The important call is cap_convert_nscap, which checks for namespace-related permissions.
If we set up file functionality from our own namespaces and mounts, there will be no problem, and we have permission to do so. But when OverlayFS forwards this operation to the underlying file system, it only calls vfs_setxattr and skips the check in cap_convert_nscap.
This allows arbitrary functionality to be set on files in the external namespace / mount and applied during execution.
In Linux 5.11, the call to cap_convert_nscap is moved to vfs_setxattr, and the attack is difficult to implement.
four。 Vulnerability exploitation
Test environment: Ubuntu 18.04LTS
Local users log in to the system and run POC.
five。 Defense advice
Update the system package version.
After reading the above, have you mastered how to carry out CVE-2021-3493 early warning of Ubuntu vulnerabilities? If you want to learn more skills or want to know more about it, you are welcome to follow the industry information channel, thank you for reading!
Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.
Views: 0
*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

The market share of Chrome browser on the desktop has exceeded 70%, and users are complaining about
The world's first 2nm mobile chip: Samsung Exynos 2600 is ready for mass production.According to a r
A US federal judge has ruled that Google can keep its Chrome browser, but it will be prohibited from
Continue with the installation of the previous hadoop.First, install zookooper1. Decompress zookoope





About us Contact us Product review car news thenatureplanet
More Form oMedia: AutoTimes. Bestcoffee. SL News. Jarebook. Coffee Hunters. Sundaily. Modezone. NNB. Coffee. Game News. FrontStreet. GGAMEN
© 2024 shulou.com SLNews company. All rights reserved.