{"id":"CVE-2021-3156","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-3156","summary":null,"details":"Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.","published":"2021-01-26T21:15:12.987Z","modified":"2026-07-08T05:59:12.314299609Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99969,"percentile":0.99977,"asOf":"2026-08-28"},"cisaKev":{"dateAdded":"2022-04-06","dueDate":"2022-04-27","knownRansomwareCampaignUse":false},"exploitsKnown":83,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3156"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/Feb/42"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/01/27/1"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/01/27/2"},{"type":"ADVISORY","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10348"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202101-33"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210128-0001/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210128-0002/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT212177"},{"type":"ADVISORY","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM"},{"type":"ADVISORY","url":"https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4839"},{"type":"ADVISORY","url":"https://www.kb.cert.org/vuls/id/794544"},{"type":"ADVISORY","url":"https://www.sudo.ws/stable.html#1.9.5p2"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_21_02"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2021/09/14/2"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/01/30/8"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2021/Jan/79"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2024/Feb/3"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2021/01/26/3"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2021/02/15/1"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2024/01/30/6"},{"type":"EVIDENCE","url":"https://www.openwall.com/lists/oss-security/2021/01/26/3"},{"type":"EVIDENCE","url":"https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:59:12.314299609Z"}}