CVE-2021-3156: Sudo Baron Samedit
A heap-based buffer overflow in sudo's command-line argument parsing, triggered when sudo is run in shell mode (sudo -s or sudoedit -s) with an argument that ends in a single unescaped backslash. Any local user, without needing to be listed in sudoers, can exploit it to escalate to root.
View the authoritative record on NVD ↗Affected software
- sudo 1.8.2 through 1.8.31p2
- sudo 1.9.0 through 1.9.5p1
How it's exploited
Invoke sudo in shell mode with an argument crafted so an off-by-one error in escaped-character counting triggers a heap buffer overflow, then use the overflow to overwrite adjacent heap memory and gain root.
Severity
CVE-2021-3156 carries a CVSS 3.1 base score of 7.8, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-3156 is categorized under CWE-193, CWE-787, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to sudo 1.9.5p2 or later, or apply the vendor-backported patch for older distribution branches.
Frequently asked questions
What is CVE-2021-3156?
A heap-based buffer overflow in sudo's command-line argument parsing, triggered when sudo is run in shell mode (sudo -s or sudoedit -s) with an argument that ends in a single unescaped backslash. Any local user, without needing to be listed in sudoers, can exploit it to escalate to root.
How severe is CVE-2021-3156?
CVE-2021-3156 has a CVSS 3.1 base score of 7.8 out of 10, rated High.
What software is affected by CVE-2021-3156?
CVE-2021-3156 affects sudo 1.8.2 through 1.8.31p2; sudo 1.9.0 through 1.9.5p1.
How do you fix CVE-2021-3156?
Upgrade to sudo 1.9.5p2 or later, or apply the vendor-backported patch for older distribution branches.
Where is the authoritative record for CVE-2021-3156?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-3156 at https://nvd.nist.gov/vuln/detail/CVE-2021-3156, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest