{
  "id": "CVE-2021-3156",
  "url": "https://spydr.io/cve/CVE-2021-3156",
  "published": "2021-01-26T21:15:12.987Z",
  "modified": "2026-06-17T04:04:45.830Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.99962,
  "epss_percentile": 0.99976,
  "exploited": true,
  "kev": {
    "added": "2022-04-06",
    "due": "2022-04-27",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Sudo Heap-Based Buffer Overflow Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-3156"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "sudo project",
    "fedoraproject",
    "debian",
    "netapp",
    "mcafee",
    "synology",
    "beyondtrust",
    "oracle"
  ],
  "products": [
    "sudo project sudo",
    "fedoraproject fedora",
    "debian linux",
    "netapp active iq unified manager",
    "netapp cloud backup",
    "netapp hci management node",
    "netapp oncommand unified manager core package",
    "netapp ontap select deploy administration utility",
    "netapp ontap tools",
    "netapp solidfire",
    "mcafee web gateway",
    "synology diskstation manager unified controller",
    "synology diskstation manager",
    "synology skynas firmware",
    "synology vs960hd firmware",
    "beyondtrust privilege management for mac",
    "beyondtrust privilege management for unix/linux",
    "oracle micros compact workstation 3 firmware",
    "oracle micros es400 firmware",
    "oracle micros kitchen display system firmware"
  ],
  "cwes": [
    "CWE-193"
  ],
  "description": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Feb/42",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Jan/79",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Feb/3",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/01/26/3",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/01/27/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/01/27/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/02/15/1",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/09/14/2",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/01/30/6",
      "tags": [
        "Exploit",
        "Mailing List"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/01/30/8",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10348",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/",
      "tags": [
        "Mailing List",
        "Release Notes"
      ]
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/",
      "tags": [
        "Mailing List",
        "Release Notes"
      ]
    },
    {
      "url": "https://security.gentoo.org/glsa/202101-33",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210128-0001/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210128-0002/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://support.apple.com/kb/HT212177",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability",
      "tags": [
        "Third Party Advisory"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3156",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
