CVE-2021-3156

sudo project sudo, fedoraproject fedora, debian linux

Published 26 Jan 2021 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 6 Apr 2022, with a remediation deadline of 27 Apr 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

References