Junglewise Threat Intelligence

CVE-2021-3156: Sudo Heap-Based Buffer Overflow Vulnerability

CVE-2021-3156 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-06

Technologies: Sudo Project Sudo. Vendors: Sudo.

Executive brief

Sudo contains an off-by-one error leading to a heap-based buffer overflow. An attacker can achieve root privilege escalation by using 'sudoedit -s' with a command-line argument ending in a single backslash.

Affected products

  • Sudo Project Sudo before 1.9.5p2

Timeline

  • 2021-01-26: disclosed: Initial public disclosure via Openwall and other sources.
  • 2022-04-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-04-06: other: Published date listed in advisory.

Related threats