CVE Vulnerabilities

CVE-2023-27320

Double Free

Published: Feb 28, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Sudo Sudo_project 1.9.8 (including) 1.9.13 (excluding)
Sudo Sudo_project 1.9.13 (including) 1.9.13 (including)
Sudo Sudo_project 1.9.13-p1 (including) 1.9.13-p1 (including)
Sudo Ubuntu devel *
Sudo Ubuntu jammy *
Sudo Ubuntu kinetic *
Sudo Ubuntu lunar *
Sudo Ubuntu trusty *
Sudo Ubuntu upstream *

Potential Mitigations

References