Sudo Project
Sudo Project Sudo: vulnerabilidades y CVE
Sudo Project Sudo tiene 24 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses1
Críticas0
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2021-3156 | Alta (7.8) | 100% | ⚠ Explotación activa | 26 ene 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-35535 | Alta (7.8) | 0.18% | — | 3 abr 2026 | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2025-32462 | Alta (8.8) | 4.4% | — | 30 jun 2025 | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. |
| CVE-2023-7090 | Alta (8.8) | 0.69% | — | 23 dic 2023 | A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where… |
| CVE-2023-42465 | Alta (7) | 0.54% | — | 22 dic 2023 | Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value),… |
| CVE-2023-28487 | Media (5.3) | 0.95% | — | 16 mar 2023 | Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
| CVE-2023-28486 | Media (5.3) | 0.92% | — | 16 mar 2023 | Sudo before 1.9.13 does not escape control characters in log messages. |
| CVE-2023-27320 | Alta (7.2) | 1.7% | — | 28 feb 2023 | Sudo before 1.9.13p2 has a double free in the per-command chroot feature. |
| CVE-2023-22809 | Alta (7.8) | 55% | — | 18 ene 2023 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary… |
| CVE-2022-43995 | Alta (7.1) | 0.28% | — | 2 nov 2022 | Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local… |
| CVE-2021-3156 | Alta (7.8) | 100% | ⚠ Explotación activa | 26 ene 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash… |
| CVE-2021-23240 | Alta (7.8) | 1.1% | — | 12 ene 2021 | selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This… |
| CVE-2021-23239 | Baja (2.5) | 1.0% | — | 12 ene 2021 | The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a… |
| CVE-2019-18634 | Alta (7.8) | 19% | — | 29 ene 2020 | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,… |
| CVE-2005-4890 | Alta (7.8) | 0.63% | — | 4 nov 2019 | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into… |
| CVE-2019-18684 | Alta (7) | 0.29% | — | 4 nov 2019 | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and… |
| CVE-2019-14287 | Alta (8.8) | 64% | — | 17 oct 2019 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For… |
| CVE-2016-7076 | Alta (7.8) | 0.49% | — | 29 may 2018 | sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such… |
| CVE-2015-8239 | Alta (7) | 0.54% | — | 10 oct 2017 | The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed. |
| CVE-2017-1000368 | Alta (8.2) | 0.57% | — | 5 jun 2017 | Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution. |
| CVE-2017-1000367 | Media (6.4) | 8.0% | — | 5 jun 2017 | Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution. |
| CVE-2014-9680 | Baja (3.3) | 0.47% | — | 24 abr 2017 | sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program… |
| CVE-2015-5602 | Alta (7.2) | 1.5% | — | 17 nov 2015 | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt." |
| CVE-2002-0184 | Alta (7.8) | 1.2% | — | 16 may 2002 | Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.