CVE-2023-27320
published 2023-02-28CVE-2023-27320: Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
PriorityP341high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.66%
74.2th percentile
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.9.13p3-1 (bookworm) | sudo 1.9.13p3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_sudo_1.9.13p3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_sudo_1.9.13p3-1_on_cbl_mariner_1.0 | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.9.13p3-1 | 1.9.13p3-1 |
| sudo_project | sudo | >= 0 < 1.9.13p3-1 | 1.9.13p3-1 |
| sudo_project | sudo | >= 0 < 1.9.13p3-1 | 1.9.13p3-1 |
| sudo_project | sudo | >= 1.9.8 < 1.9.13 | 1.9.13 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_debian7.2HIGH
vendor_msrc7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8wp-rv4w-h5pp: Sudo before 1
ghsa_unreviewed·2023-02-28
CVE-2023-27320 [HIGH] CWE-415 GHSA-w8wp-rv4w-h5pp: Sudo before 1
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
OSV
CVE-2023-27320: Sudo before 1
osv·2023-02-28·CVSS 7.2
CVE-2023-27320 [HIGH] CVE-2023-27320: Sudo before 1
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Ubuntu
Sudo vulnerability
vendor_ubuntu·2023-03-02
CVE-2023-27320 Sudo vulnerability
Title: Sudo vulnerability
Summary: Sudo could be made to crash or escalate privileges.
It was discovered that Sudo incorrectly handled the per-command chroot
feature. In certain environments where Sudo is configured with a rule that
contains a CHROOT setting, a local attacker could use this issue to cause
Sudo to crash, resulting in a denial of service, or possibly escalate
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: double free with per-command chroot sudoers rules
vendor_redhat·2023-02-28·CVSS 7.2
CVE-2023-27320 [HIGH] CWE-415 sudo: double free with per-command chroot sudoers rules
sudo: double free with per-command chroot sudoers rules
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
A double-free vulnerability was found in Sudo in the per-command chroot feature. This flaw exists due to a boundary error when matching a sudoer rule that contains a per-command chroot directive (CHROOT=dir). By sending a specially-crafted request, a local privileged attacker can elevate privileges and execute arbitrary code on the system.
Statement: The CHROOT support was only added in Sudo v1.9.3 and Sudo v1.9.8 included a fix for a memory leak in the set_cmnd_path() function, which can result in the "user_cmnd" variable being freed twice, but only when processing a sudoers rule that contains a "CHROOT" setting. This does not affect the "chroot" Defaults se
Microsoft
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
vendor_msrc·2023-02-14·CVSS 7.2
CVE-2023-27320 [HIGH] CWE-415 Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refere
Debian
CVE-2023-27320: sudo - Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
vendor_debian·2023·CVSS 7.2
CVE-2023-27320 [HIGH] CVE-2023-27320: sudo - Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Scope: local
bookworm: resolved (fixed in 1.9.13p3-1)
bullseye: resolved
forky: resolved (fixed in 1.9.13p3-1)
sid: resolved (fixed in 1.9.13p3-1)
trixie: resolved (fixed in 1.9.13p3-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/03/01/8https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/https://security.gentoo.org/glsa/202309-12https://security.netapp.com/advisory/ntap-20230413-0009/https://www.openwall.com/lists/oss-security/2023/02/28/1https://www.sudo.ws/releases/stable/#1.9.13p2http://www.openwall.com/lists/oss-security/2023/03/01/8https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/https://security.gentoo.org/glsa/202309-12https://security.netapp.com/advisory/ntap-20230413-0009/https://www.openwall.com/lists/oss-security/2023/02/28/1https://www.sudo.ws/releases/stable/#1.9.13p2
2023-02-28
Published