VYPR
Unrated severityCISA KEVNVD Advisory· Published Jan 26, 2021· Updated Oct 21, 2025

CVE-2021-3156

CVE-2021-3156

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Affected products

1
  • Sudo/Sudodescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

34

News mentions

0

No linked articles in our index yet.