CVE Vulnerabilities

CVE-2023-27320

Double Free

Published: Feb 28, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Sudo Sudo_project 1.9.8 (including) 1.9.13 (excluding)
Sudo Sudo_project 1.9.13 (including) 1.9.13 (including)
Sudo Sudo_project 1.9.13-p1 (including) 1.9.13-p1 (including)

Potential Mitigations

References