logo

Recent Linux sudo vulnerability affects a major percent of cloud workloads

ID: 9f2b49c9-75cd-559e-9bae-6b5cffcdbcac

STIX ID: report--9f2b49c9-75cd-559e-9bae-6b5cffcdbcac

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2021-02-02

Date Updated: 2026-05-01

...
...

CVE-2021-3156 is a high-severity local privilege escalation vulnerability in the ubiquitous sudo utility that allows an unprivileged local user to escalate to root without authentication. The report lists affected sudo versions (1.8.2–1.8.31p2 and 1.9.0–1.9.5p1), describes the underlying escape/unescape parsing bug triggered by sudoedit when shell mode is set, provides a simple local test (run “sudoedit -s/”), highlights broad impact across Linux cloud workloads, and recommends rapid scanning and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.