CVE-2021-3156 sudo Vulnerability Allows Root Privileges
ID: 82cf670d-729d-580b-84c9-6f0472842033
STIX ID: report--82cf670d-729d-580b-84c9-6f0472842033
Feed Name: Aqua Security Blog
Threat Score
A critical heap-overflow vulnerability in sudo (affecting legacy versions 1.8.2–1.8.31p2 and stable versions 1.9.0–1.9.5p1) allows an unprivileged user — including in non-privileged containers — to escalate to root or be added to sudoers by abusing sudoedit with a trailing unescaped backslash; the report explains reproduction/testing commands, affected versions, mitigation via blocking sudoedit in runtime/host policies or applying vendor patches, and links to vendor advisories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
