CVE Vulnerabilities

CVE-2021-3156

Off-by-one Error

Published: Jan 26, 2021 | Modified: Jan 14, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
HIGH

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via sudoedit -s and a command-line argument that ends with a single backslash character.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

Name Vendor Start Version End Version
Sudo Sudo_project 1.8.2 (including) 1.8.32 (excluding)
Sudo Sudo_project 1.9.0 (including) 1.9.5 (excluding)
Sudo Sudo_project 1.9.5 (including) 1.9.5 (including)
Sudo Sudo_project 1.9.5-patch1 (including) 1.9.5-patch1 (including)
Red Hat Enterprise Linux 6 Extended Lifecycle Support RedHat sudo-0:1.8.6p3-29.el6_10.4 *
Red Hat Enterprise Linux 7 RedHat sudo-0:1.8.23-10.el7_9.1 *
Red Hat Enterprise Linux 7.2 Advanced Update Support RedHat sudo-0:1.8.6p7-17.el7_2.3 *
Red Hat Enterprise Linux 7.3 Advanced Update Support RedHat sudo-0:1.8.6p7-23.el7_3.3 *
Red Hat Enterprise Linux 7.4 Advanced Update Support RedHat sudo-0:1.8.19p2-12.el7_4.2 *
Red Hat Enterprise Linux 7.4 Telco Extended Update Support RedHat sudo-0:1.8.19p2-12.el7_4.2 *
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions RedHat sudo-0:1.8.19p2-12.el7_4.2 *
Red Hat Enterprise Linux 7.6 Extended Update Support RedHat sudo-0:1.8.23-3.el7_6.2 *
Red Hat Enterprise Linux 7.7 Extended Update Support RedHat sudo-0:1.8.23-4.el7_7.3 *
Red Hat Enterprise Linux 8 RedHat sudo-0:1.8.29-6.el8_3.1 *
Red Hat Enterprise Linux 8.1 Extended Update Support RedHat sudo-0:1.8.25p1-8.el8_1.2 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat sudo-0:1.8.29-5.el8_2.1 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-virtualization-host-0:4.3.13-20210127.0.el7_9 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 RedHat redhat-virtualization-host-0:4.4.4-20210201.0.el8_3 *
Sudo Ubuntu bionic *
Sudo Ubuntu devel *
Sudo Ubuntu focal *
Sudo Ubuntu groovy *
Sudo Ubuntu trusty *
Sudo Ubuntu trusty/esm *
Sudo Ubuntu upstream *
Sudo Ubuntu xenial *

Potential Mitigations

References