Exploited Vulnerabilities Daily
🌐 English

Home › Sudo

CVE-2021-3156: Sudo Sudo

EPSS99.9%No. 91 of 1739 in KEV
CVE year2021~1 yrs before listing
Same vendor in KEV2
Same product2
FieldValue
VendorSudo
ProductSudo
NameSudo Heap-Based Buffer Overflow Vulnerability
Added to KEV2022-04-06
US federal due date2022-04-27
Ransomware useUnknown
CWECWE-122, CWE-193

CISA description

Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2025-32463Sudo Sudo2025-09-2955.4%Unknown

NVD — CVE-2021-3156

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Sudo Sudo vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-06.