CVE-2021-3156 - CVE House
Back to Database
Status published Unknown CVE-2021-3156

Sudo before 1.9.5p2 contains an off-by-one error that can result...

Vulnerability Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3156

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

sudo project

View all reports →

Affected Software

sudo, fedora, debian linux, active iq unified manager, cloud backup, hci management node, oncommand unified manager core package, ontap select deploy administration utility, ontap tools, solidfire, web gateway, diskstation manager unified controller, diskstation manager, skynas firmware, vs960hd firmware, privilege management for mac, privilege management for unix\/linux, micros compact workstation 3 firmware, micros es400 firmware, micros kitchen display system firmware, micros workstation 5a firmware, micros workstation 6 firmware, communications performance intelligence center, tekelec platform distribution
Vulnerable Versions:
1.8.2, 1.9.0, 1.9.5, 32, 33, 9.0, 10.0, 9, 8.2.17, 9.2.8, 10.0.4, 3.0, 6.2, 0, 310, 400, 210, 5a, 610, 10.3.0.0.0, 10.4.0.1.0, 7.4.0

Timeline

Official Publish: January 26th, 2021
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.