CVE Vulnerabilities

CVE-2021-3156

Off-by-one Error

Published: Jan 26, 2021 | Modified: Nov 10, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via sudoedit -s and a command-line argument that ends with a single backslash character.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
SudoSudo_project1.8.2 (including)1.8.32 (excluding)
SudoSudo_project1.9.0 (including)1.9.5 (excluding)
SudoSudo_project1.9.5 (including)1.9.5 (including)
SudoSudo_project1.9.5-patch1 (including)1.9.5-patch1 (including)
Red Hat Enterprise Linux 6 Extended Lifecycle SupportRedHatsudo-0:1.8.6p3-29.el6_10.4*
Red Hat Enterprise Linux 7RedHatsudo-0:1.8.23-10.el7_9.1*
Red Hat Enterprise Linux 7.2 Advanced Update SupportRedHatsudo-0:1.8.6p7-17.el7_2.3*
Red Hat Enterprise Linux 7.3 Advanced Update SupportRedHatsudo-0:1.8.6p7-23.el7_3.3*
Red Hat Enterprise Linux 7.4 Advanced Update SupportRedHatsudo-0:1.8.19p2-12.el7_4.2*
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportRedHatsudo-0:1.8.19p2-12.el7_4.2*
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsRedHatsudo-0:1.8.19p2-12.el7_4.2*
Red Hat Enterprise Linux 7.6 Extended Update SupportRedHatsudo-0:1.8.23-3.el7_6.2*
Red Hat Enterprise Linux 7.7 Extended Update SupportRedHatsudo-0:1.8.23-4.el7_7.3*
Red Hat Enterprise Linux 8RedHatsudo-0:1.8.29-6.el8_3.1*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatsudo-0:1.8.25p1-8.el8_1.2*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatsudo-0:1.8.29-5.el8_2.1*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-virtualization-host-0:4.3.13-20210127.0.el7_9*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatredhat-virtualization-host-0:4.4.4-20210201.0.el8_3*
SudoUbuntubionic*
SudoUbuntudevel*
SudoUbuntuesm-infra-legacy/trusty*
SudoUbuntuesm-infra/bionic*
SudoUbuntuesm-infra/focal*
SudoUbuntuesm-infra/xenial*
SudoUbuntufocal*
SudoUbuntugroovy*
SudoUbuntutrusty*
SudoUbuntutrusty/esm*
SudoUbuntuupstream*
SudoUbuntuxenial*

Potential Mitigations

References