⚠ Actively exploited
Added to CISA KEV on 2022-04-06. Federal agencies required to patch by 2022-04-27. Required action: Apply updates per vendor instructions..
Severity
7.8HIGH
EPSS
92.3%
top 0.28%
CISA KEV
KEV
Added 2022-04-06
Due 2022-04-27
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 26
KEV addedApr 6
KEV dueApr 27
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages14 packages

NVDsudo_project/sudo1.8.21.8.32+2
Debiansudo< 1.9.5p1-1.1+3
Ubuntusudo< 1.8.16-0ubuntu1.10+3

Also affects: Ontap Tools 9, Debian Linux 10.0, 9.0, Fedora 32, 33

Patches

🔴Vulnerability Details

6
GHSA
GHSA-w5vh-2923-gp5c: Sudo before 12022-05-24
OSV
sudo vulnerability2021-01-27
OSV
sudo vulnerabilities2021-01-26
OSV
CVE-2021-3156: Sudo before 12021-01-26
CVEList
CVE-2021-3156: Sudo before 12021-01-26

💥Exploits & PoCs

3
Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)2021-02-03
Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)2021-02-03
Nuclei
Sudo Baron Samedit - Local Privilege Escalation

🔍Detection Rules

3
YARA
Linux_Exploit_CVE_2021_3156_7f5672d0
YARA
Linux_Exploit_CVE_2021_3156_f3fb10cd
Elastic
Deprecated - Sudo Heap-Based Buffer Overflow Attempt

📋Vendor Advisories

9
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Sudo) — CVE-2021-31562022-04-15
CISA
Sudo Heap-Based Buffer Overflow Vulnerability2022-04-06
Oracle
Oracle Oracle Communications Risk Matrix: Storage Management (Sudo) — CVE-2021-31562021-10-15
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Workstation 310 (Sudo) — CVE-2021-31562021-07-15
Cisco
Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 20212021-01-29

🕵️Threat Intelligence

5
Wiz
Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog2021-02-02
Wiz
Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog2021-02-02
Qualys
Sudo Vulnerability CVE-2021-3156: Root Access Risk | Qualys2021-01-26
Qualys
CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)2021-01-26
Huntress
CVE-2021-3156 Vulnerability: Analysis, Impact, Mitigation | Huntress