Vulnerability Intelligence Report
Sudo Heap-Based Buffer Overflow Vulnerability
CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:99.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-193 ↗CWE-193 Off-by-one Error
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| sudo_project | sudo | 1.9.5 |
| fedoraproject | fedora | 32, 33 |
| debian | debian_linux | 9.0, 10.0 |
| netapp | active_iq_unified_manager | all |
| netapp | cloud_backup | all |
| netapp | hci_management_node | all |
| netapp | oncommand_unified_manager_core_package | all |
| netapp | ontap_select_deploy_administration_utility | all |
| netapp | ontap_tools | 9 |
| netapp | solidfire | all |
| mcafee | web_gateway | 8.2.17, 9.2.8, 10.0.4 |
| synology | diskstation_manager_unified_controller | 3.0 |
| synology | diskstation_manager | 6.2 |
| synology | skynas_firmware | all |
| synology | skynas | all |
| synology | vs960hd_firmware | all |
| synology | vs960hd | all |
| beyondtrust | privilege_management_for_mac | all |
| beyondtrust | privilege_management_for_unix\/linux | all |
| oracle | micros_compact_workstation_3_firmware | 310 |
| oracle | micros_compact_workstation_3 | all |
| oracle | micros_es400_firmware | all |
| oracle | micros_es400 | all |
| oracle | micros_kitchen_display_system_firmware | 210 |
| oracle | micros_kitchen_display_system | all |
| oracle | micros_workstation_5a_firmware | 5a |
| oracle | micros_workstation_5a | all |
| oracle | micros_workstation_6_firmware | all |
| oracle | micros_workstation_6 | all |
| oracle | communications_performance_intelligence_center | all |
| oracle | tekelec_platform_distribution | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.305%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2021-01-15T00:00:00 |
| Published | 2021-01-26T00:00:00 |
| Last Updated | 2025-10-21T23:35:29 |
Community Chatter & Buzz