CISA added CVE-2021-3493 to its Known Exploited Vulnerabilities (KEV) Catalog after evidence showed it was being exploited. The Linux kernel flaw can let a local, unprivileged user gain root privileges. SecurityWeek linked its use to Shikitega malware, which also used the separate PwnKit vulnerability, CVE-2021-4034, in an infection chain. The practical response is to install the security update for each affected Ubuntu release and investigate systems that may have been compromised; installing a patch alone does not establish that a host is clean.
What is CVE-2021-3493?
CVE-2021-3493 is a local privilege-escalation vulnerability in the Linux kernel’s OverlayFS implementation. An attacker needs an existing low-privilege foothold on a system; this is not a remote, unauthenticated network flaw. If exploited, it can allow that user to gain root-level privileges.
Ubuntu’s Security Team explains that the kernel did not properly validate the setting of file capabilities on files in an underlying filesystem with respect to user namespaces. The privilege escalation involved unprivileged user namespaces together with an Ubuntu kernel patch that allowed unprivileged overlay mounts. The issue therefore should not be treated as affecting every Linux distribution: the reported scope centered on Ubuntu kernels carrying the relevant behavior. Check Ubuntu’s advisory for the status of a specific release and package track: Ubuntu CVE-2021-3493 advisory.
Why did CISA issue the warning?
CISA’s KEV Catalog is a prioritization resource for vulnerabilities with evidence of exploitation in the wild. CISA directs federal agencies covered by Binding Operational Directive 22-01 to remediate catalog entries on its schedule and also urges organizations outside the federal government to prioritize timely remediation.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
- A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
- 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
- Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
- Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
SecurityWeek reported on October 21, 2022 that CISA had added CVE-2021-3493 to the catalog. The coverage connected exploitation to Shikitega, a stealthy Linux malware family targeting Linux endpoints and IoT devices. The reported infection chain used CVE-2021-3493 alongside CVE-2021-4034, known as PwnKit, for privilege escalation and could download a cryptocurrency miner. The report does not establish an incident-wide infection count or total number of affected devices.
Is an Ubuntu system vulnerable?
Do not infer exposure from the word “Linux” alone or rely on a kernel version copied from an old article. Ubuntu’s advisory lists CVE-2021-3493 as high priority and gives it a CVSS 3 score of 8.8 in its 2026 update. It identifies fixed package builds including linux 5.4.0-72.80 for Ubuntu 20.04 and linux 4.15.0-142.146 for Ubuntu 18.04, as well as corresponding fixed builds for other affected Ubuntu package tracks. These are advisory examples, not universal current targets for every installation.
Rank #2
- Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
- 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
- Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
- I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
- Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad
Check the current Ubuntu notice against the release and kernel package actually installed on each machine. This matters for cloud images, appliances, endpoints, and IoT devices as well as conventional servers: a fleet may contain multiple Ubuntu releases or package tracks, and an old image may not reflect the current security status.
How to respond
- Inventory Ubuntu systems. Include cloud instances and images, appliances, employee endpoints, and IoT devices. Identify each system’s Ubuntu release and installed kernel package.
- Compare installed packages with Ubuntu’s current advisory. Use the entry for CVE-2021-3493 and the relevant release’s package track rather than treating a version cited in older reporting as the right target today.
- Install the vendor security update. Use the normal package-management and change-control process for the system. Reboot where the distribution requires it so the updated kernel is running.
- Verify deployment across the fleet. Confirm that each in-scope system received the applicable update and, where required, rebooted into the updated kernel. Track exceptions and failed updates instead of assuming a rollout succeeded.
- Review security telemetry. Examine authentication events, process activity, persistence mechanisms, and outbound network connections for signs of local privilege escalation, Shikitega components, or cryptocurrency-mining activity.
- Handle suspected compromise as an incident. Isolate the host under your incident-response procedures, preserve relevant evidence, and rotate credentials that may have been exposed. Return it to service only after validation.
What patching does—and does not—confirm
Installing the fixed kernel package addresses the known vulnerability on that system, but it cannot undo exploitation that happened before the update. A host that may have been accessed through the flaw still needs investigation for malware, persistence, stolen credentials, and other unauthorized changes. Treat patch verification and compromise assessment as separate tasks.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
- Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
- 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
- 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
- I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
- Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging
For organizational context, see CISA’s Known Exploited Vulnerabilities Catalog and the Ubuntu security notice for the package status relevant to your release.
Quick Recap
Best Value
- 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
- 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
- Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
- Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
- GMKtec WARRANTY - GMKtec offers a 1-year limited GMKtec's warranty for each mini PC, starting from the date of the purchase. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC.
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

