cbcvebase.

Debian Sudo vulnerabilities

46 known vulnerabilities affecting debian/sudo.

Total CVEs
46
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
HIGH13MEDIUM20LOW13

Vulnerabilities

Page 1 of 3
CVE-2021-3156P1HIGHCVSS 7.8KEVPoCfixed in sudo 1.9.5p1-1.1 (bookworm)2021
CVE-2021-3156 [HIGH] CVE-2021-3156: sudo - Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based... Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. Scope: local bookworm: resolved (fixed in 1.9.5p1-1.1) bullseye: resolved (fixed in 1.9.5p1-1.1) forky: resolved (fixed in 1.9.5p1-1.1) sid: r
debian
CVE-2025-32463P1LOWCVSS 9.3KEVPoCfixed in sudo 1.9.16p2-3 (forky)2025
CVE-2025-32463 [CRITICAL] CVE-2025-32463: sudo - Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswi... Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1.9.16p2-3) sid: resolved (fixed in 1.9.16p2-3) trixie: resolved (fixed in 1.9.16p2-3)
debian
CVE-2023-22809P1HIGHCVSS 7.8ExploitedPoCfixed in sudo 1.9.12p2-1 (bookworm)2023
CVE-2023-22809 [HIGH] CVE-2023-22809: sudo - In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra argument... In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a us
debian
CVE-2017-1000367P2MEDIUMCVSS 6.4ExploitedPoCfixed in sudo 1.8.20p1-1 (bookworm)2017
CVE-2017-1000367 [MEDIUM] CVE-2017-1000367: sudo - Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validati... Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution. Scope: local bookworm: resolved (fixed in 1.8.20p1-1) bullseye: resolved (fixed in 1.8.20p1-1) forky: resolved (fixed in 1.8.20p1-1) sid: resolved (fixed in 1.8.20p1-1
debian
CVE-2019-14287P2HIGHCVSS 8.8PoCfixed in sudo 1.8.27-1.1 (bookworm)2019
CVE-2019-14287 [HIGH] CVE-2019-14287: sudo - In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can... In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command. Scope: local bookworm: resolved (fixed i
debian
CVE-2019-18634P2HIGHCVSS 7.8PoCfixed in sudo 1.8.31-1 (bookworm)2019
CVE-2019-18634 [HIGH] CVE-2019-18634: sudo - In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigg... In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long
debian
CVE-2025-32462P2LOWCVSS 2.8PoCfixed in sudo 1.9.13p3-1+deb12u2 (bookworm)2025
CVE-2025-32462 [LOW] CVE-2025-32462: sudo - Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that i... Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. Scope: local bookworm: resolved (fixed in 1.9.13p3-1+deb12u2) bullseye: resolved (fixed in 1.9.5p2-3+deb11u2) forky: resolved (fixed in 1.9.16p2-3) sid: resolved (fixed in 1.9.16p2-3) trixie:
debian
CVE-2012-0809P3HIGHCVSS 7.2PoCfixed in sudo 1.8.3p2-1 (bookworm)2012
CVE-2012-0809 [HIGH] CVE-2012-0809: sudo - Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8... Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo. Scope: local bookworm: resolved (fixed in 1.8.3p2-1) bullseye: resolved (fixed in 1.8.3p2-1) forky: resolved (fixed in 1.8.3p2-1) sid: resolved (fixed in 1.8.3p2-1) trixie: resolved (fi
debian
CVE-2015-5602P3HIGHCVSS 7.2PoCfixed in sudo 1.8.15-1.1 (bookworm)2015
CVE-2015-5602 [HIGH] CVE-2015-5602: sudo - sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symli... sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt." Scope: local bookworm: resolved (fixed in 1.8.15-1.1) bullseye: resolved (fixed in 1.8.15-1.1) forky: resolved (fixed in 1.8.15-1.1) sid: resolved (fixed in 1.8.15
debian
CVE-2013-1775P4MEDIUMCVSS 6.9PoCfixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-1775 [MEDIUM] CVE-2013-1775: sudo - sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or... sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. Scope: local bookworm: resolved (fixed in 1.8.5p2-1+nmu1) bullseye: resolved (fixed in 1.8.5p2-1+nmu1) forky
debian
CVE-2023-7090P3MEDIUMCVSS 6.6fixed in sudo 1.8.28p1-1 (bookworm)2023
CVE-2023-7090 [MEDIUM] CVE-2023-7090: sudo - A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname fro... A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them. Scope: local bookworm: resolved (fixed in 1.8.28p1-1) bullseye: resolved (fixed in 1.8.28p1-1) for
debian
CVE-2019-19232P3LOWCVSS 7.5fixed in sudo 1.8.31-1 (bookworm)2019
CVE-2019-19232 [HIGH] CVE-2019-19232: sudo - In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account ca... In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional featur
debian
CVE-2019-19234P3LOWCVSS 7.5fixed in sudo 1.8.31-1 (bookworm)2019
CVE-2019-19234 [HIGH] CVE-2019-19234: sudo - In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using th... In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software maintainer believes that this CVE is not valid. Disabling local password authentication for
debian
CVE-2021-23240P3LOWCVSS 7.8fixed in sudo 1.9.5-1 (bookworm)2021
CVE-2021-23240 [HIGH] CVE-2021-23240: sudo - selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivi... selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable. Scope: local bookworm: resolved (fixed in 1.9.5-1) bullseye:
debian
CVE-2023-27320P3HIGHCVSS 7.2fixed in sudo 1.9.13p3-1 (bookworm)2023
CVE-2023-27320 [HIGH] CVE-2023-27320: sudo - Sudo before 1.9.13p2 has a double free in the per-command chroot feature. Sudo before 1.9.13p2 has a double free in the per-command chroot feature. Scope: local bookworm: resolved (fixed in 1.9.13p3-1) bullseye: resolved forky: resolved (fixed in 1.9.13p3-1) sid: resolved (fixed in 1.9.13p3-1) trixie: resolved (fixed in 1.9.13p3-1)
debian
CVE-2026-35535P3HIGHCVSS 7.4fixed in sudo 1.9.17p2-5 (forky)2026
CVE-2026-35535 [HIGH] CVE-2026-35535: sudo - In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgr... In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.9.17p2-5) sid: resolved (fixed in 1.9.17p2-5) trixie: open
debian
CVE-2005-4158P4MEDIUMCVSS 4.6PoCfixed in sudo 1.6.8p12-1 (bookworm)2005
CVE-2005-4158 [MEDIUM] CVE-2005-4158: sudo - Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) P... Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script. Scope: local bookworm: resolved (fixed in 1.6.8p12-1
debian
CVE-2016-7076P3MEDIUMCVSS 6.4fixed in sudo 1.8.18p1-1 (bookworm)2016
CVE-2016-7076 [MEDIUM] CVE-2016-7076: sudo - sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restri... sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges. Scope: local bookworm:
debian
CVE-2005-4890P3LOWCVSS 7.8fixed in shadow 1:4.1.5-1 (bookworm)2005
CVE-2005-4890 [HIGH] CVE-2005-4890: shadow - There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before... There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process. Scope: local bookworm: resolved (fixed in 1:4.1.5-1) bullseye: resolved (fixed in 1:4.1.5-1) forky: re
debian
CVE-2004-1689P4LOWCVSS 2.1PoCfixed in sudo 1.6.8p3-1 (bookworm)2004
CVE-2004-1689 [LOW] CVE-2004-1689: sudo - sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges... sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit. Scope: local bookworm: resolved (fixed in 1.6.8p3-1) bullseye: resolved (fixed in 1.6.8p3-1) forky: resolved (fixed in 1.6.8p3-1) sid: resolved (fixed in 1.6.8p3-1) trixie: r
debian