← Back to CVE List
Vulnerability Intelligence Report
Sudo Heap-Based Buffer Overflow Vulnerability

CVE-2021-3156

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:99.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-193 ↗CWE-193 Off-by-one Error

Affected Products & Versions

Vendor Product Affected Versions
sudo_project sudo 1.9.5
fedoraproject fedora 32, 33
debian debian_linux 9.0, 10.0
netapp active_iq_unified_manager all
netapp cloud_backup all
netapp hci_management_node all
netapp oncommand_unified_manager_core_package all
netapp ontap_select_deploy_administration_utility all
netapp ontap_tools 9
netapp solidfire all
mcafee web_gateway 8.2.17, 9.2.8, 10.0.4
synology diskstation_manager_unified_controller 3.0
synology diskstation_manager 6.2
synology skynas_firmware all
synology skynas all
synology vs960hd_firmware all
synology vs960hd all
beyondtrust privilege_management_for_mac all
beyondtrust privilege_management_for_unix\/linux all
oracle micros_compact_workstation_3_firmware 310
oracle micros_compact_workstation_3 all
oracle micros_es400_firmware all
oracle micros_es400 all
oracle micros_kitchen_display_system_firmware 210
oracle micros_kitchen_display_system all
oracle micros_workstation_5a_firmware 5a
oracle micros_workstation_5a all
oracle micros_workstation_6_firmware all
oracle micros_workstation_6 all
oracle communications_performance_intelligence_center all
oracle tekelec_platform_distribution all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.305%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-01-15T00:00:00
Published2021-01-26T00:00:00
Last Updated2025-10-21T23:35:29

LINK COPIED TO CLIPBOARD