CVE-2021-3156
Confirmed PUBLISHEDSudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- CVE Published
- Jan 26, 2021
- Exploitation Reported
- Apr 06, 2022
- CVSS
- 7.8 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- GLSA-202101-33 security.gentoo.org · Vendor Advisory https://security.gentoo.org/glsa/202101-33
- DSA-4839 debian.org · Vendor Advisory https://www.debian.org/security/2021/dsa-4839
- FEDORA-2021-2cb63d912a lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- FEDORA-2021-8840cbdccd lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- 20210129 Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021 tools.cisco.com · Vendor Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory...
Show 29 more references
- VU#794544 kb.cert.org · Third-Party Advisory https://www.kb.cert.org/vuls/id/794544
- [debian-lts-announce] 20210126 [SECURITY] [DLA 2534-1] sudo security update lists.debian.org · Mailing List https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html
- 20210126 Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156) seclists.org · Mailing List http://seclists.org/fulldisclosure/2021/Jan/79
- [oss-security] 20210126 Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156) openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2021/01/26/3
- [oss-security] 20210127 Re: Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156) openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2021/01/27/1
- [oss-security] 20210127 Re: Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156) openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2021/01/27/2
- 20210211 APPLE-SA-2021-02-09-1 macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, and macOS Mojave 10.14.6 Security Update 2021-002 seclists.org · Mailing List http://seclists.org/fulldisclosure/2021/Feb/42
- [oss-security] 20210215 Re: sudo: Ineffective NO_ROOT_MAILER and Baron Samedit openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2021/02/15/1
- [oss-security] 20210914 Re: Oracle Solaris membership in the distros list openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2021/09/14/2
- [oss-security] 20240130 Re: CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog() openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2024/01/30/8
- [oss-security] 20240130 CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog() openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2024/01/30/6
- 20240204 CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog() seclists.org · Mailing List http://seclists.org/fulldisclosure/2024/Feb/3
- oracle.com//security-alerts/cpujul2021.html oracle.com · CVE Record https://www.oracle.com//security-alerts/cpujul2021.html
- sudo.ws/stable.html sudo.ws · CVE Record https://www.sudo.ws/stable.html#1.9.5p2
- OSS-Security Mailing List openwall.com · CVE Record https://www.openwall.com/lists/oss-security/2021/01/26/3
- packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Ov...
- security.netapp.com/advisory/ntap-20210128-0002 security.netapp.com · CVE Record https://security.netapp.com/advisory/ntap-20210128-0002/
- security.netapp.com/advisory/ntap-20210128-0001 security.netapp.com · CVE Record https://security.netapp.com/advisory/ntap-20210128-0001/
- packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Priv...
- packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Pr... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overf...
- packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Ov... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buf...
- support.apple.com/kb/HT212177 support.apple.com · CVE Record https://support.apple.com/kb/HT212177
- kc.mcafee.com/corporate/index kc.mcafee.com · CVE Record https://kc.mcafee.com/corporate/index?page=content&id=SB10348
- beyondtrust.com/blog/entry/security-advisory-privilege-manag... beyondtrust.com · CVE Record https://www.beyondtrust.com/blog/entry/security-advisory-privilege-ma...
- synology.com/security/advisory/Synology_SA_21_02 synology.com · CVE Record https://www.synology.com/security/advisory/Synology_SA_21_02
- oracle.com/security-alerts/cpuoct2021.html oracle.com · CVE Record https://www.oracle.com/security-alerts/cpuoct2021.html
- oracle.com/security-alerts/cpuapr2022.html oracle.com · CVE Record https://www.oracle.com/security-alerts/cpuapr2022.html
- packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-B...
- vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156 vicarius.io · CVE Record https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-04-06 00:00 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/sudo_baron_samedit.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitation Status
Exploited in the wild
Recorded 2022-04-06 00:00:00 UTC · CISA
Proof of concept available
Recorded 2021-01-26 19:53:04 UTC · GitHub
Weaknesses (CWE)
-
Off-by-one Error
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/sudo_baron_samedit.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-05-13 01:02:32 UTC · 4 stars
Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts
github · Created 2022-12-25 03:58:20 UTC · 0 stars
github · Created 2022-11-03 13:10:23 UTC · 26 stars
利用sudo提权,只针对cnetos7
github · Created 2022-07-04 13:55:24 UTC · 5 stars
Visualization, Fuzzing, Exploit and Patch of Baron Samedit Vulnerability
github · Created 2022-01-27 02:31:43 UTC · 8 stars
CVE-2021-3156 POC and Docker and Analysis write up
github · Created 2021-10-13 17:43:51 UTC · 2 stars
github · Created 2021-08-07 08:38:50 UTC · 0 stars
github · Created 2021-06-30 18:00:03 UTC · 1 stars
github · Created 2021-03-19 14:06:09 UTC · 4 stars
Exploit generator for sudo CVE-2021-3156
github · Created 2021-03-15 17:37:02 UTC · 746 stars
Sudo Baron Samedit Exploit
github · Created 2021-02-23 03:14:36 UTC · 0 stars
github · Created 2021-02-09 19:25:18 UTC · 201 stars
CVE-2021-3156非交互式执行命令
github · Created 2021-02-09 07:55:47 UTC · 16 stars
sudo heap overflow to LPE, in Go
github · Created 2021-02-08 18:21:58 UTC · 51 stars
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
github · Created 2021-02-06 21:16:11 UTC · 5 stars
github · Created 2021-02-03 19:57:56 UTC · 151 stars
Root shell PoC for CVE-2021-3156
github · Created 2021-02-03 09:48:46 UTC · 5 stars
CVE-2021-3156 Vagrant Lab
github · Created 2021-01-31 22:58:13 UTC · 7 stars
A docker environment to research CVE-2021-3156
github · Created 2021-01-31 16:10:11 UTC · 3 stars
Description Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
github · Created 2021-01-31 03:38:37 UTC · 8 stars
github · Created 2021-01-30 20:39:58 UTC · 975 stars
github · Created 2021-01-30 10:53:26 UTC · 1 stars
checking CVE-2021-3156 vulnerability & patch script
github · Created 2021-01-30 03:22:04 UTC · 435 stars
PoC for CVE-2021-3156 (sudo heap overflow)
github · Created 2021-01-29 19:24:41 UTC · 38 stars
Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo
github · Created 2021-01-28 08:55:04 UTC · 4 stars
github · Created 2021-01-28 02:13:49 UTC · 18 stars
1day research effort
github · Created 2021-01-27 21:49:06 UTC · 3 stars
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
github · Created 2021-01-27 16:35:43 UTC · 1 stars
github · Created 2021-01-26 19:53:04 UTC · 35 stars
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
19:53 UTC over 5 years ago19:53 UTC · over 5 years ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC over 5 years ago00:00 UTC · over 5 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC over 5 years ago00:00 UTC · over 5 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2021-3156
{
"cve_id": "CVE-2021-3156",
"title": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-ba...",
"affected_vendor": "Sudo Project",
"affected_product": "Sudo",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}