Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3156

99
FAUCET Score

CVE-2021-3156, also known as "Baron Samedit," is a critical heap-based buffer overflow vulnerability in Sudo versions prior to 1.9.5p2, affecting numerous products including Debian, Fedora, and macOS. This flaw allows a local attacker to achieve root privilege escalation by exploiting an off-by-one error when using "sudoedit -s" with a specially crafted command-line argument. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered extensive community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.8.2, < 1.8.32CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
>= 1.9.0, < 1.9.5CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
1.9.5CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.5:-:*:*:*:*:*:*
1.9.5CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.5:patch1:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.30%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Apr 6, 2022
Metasploit: Sudo Heap-Based Buffer Overflow · Jan 26, 2021
Nuclei: CVE-2021-3156 · Dec 30, 2023
ExploitDB: EDB-49521 · Feb 3, 2021
This CVE's current EPSS score of 0.9929 is in the 100th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle SupportFixed in: sudo-0:1.8.6p3-29.el6_10.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: sudo-0:1.8.23-10.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: sudo-0:1.8.6p7-17.el7_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: sudo-0:1.8.6p7-23.el7_3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: sudo-0:1.8.19p2-12.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: sudo-0:1.8.19p2-12.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: sudo-0:1.8.19p2-12.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: sudo-0:1.8.23-3.el7_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Extended Update SupportFixed in: sudo-0:1.8.23-4.el7_7.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sudo-0:1.8.29-6.el8_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: sudo-0:1.8.25p1-8.el8_1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: sudo-0:1.8.29-5.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.13-20210127.0.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.4-20210201.0.el8_3
View patch
capnprotovendor investigatingvia llm_extracted
denovendor investigatingvia llm_extracted
View patch
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
invoiceplanevendor investigatingvia llm_extracted
View patch
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
pjsipvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted

Vendor Advisories (10)

hanwhallm-hanwha-52bcc742b4b25d7cHIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
capnprotollm-capnproto-9588a8ce023d2b33HIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
openwrtllm-openwrt-064da59f8b3f9ed5HIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
gcpllm-gcp-f281891ce77835ceHIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
kongllm-kong-0e7035995c92cb05HIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
proxmoxllm-proxmox-77597c349f5a62b7HIGH

Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products

Feb 24, 2021
redhatCVE-2021-3156Important

sudo: Heap buffer overflow in argument parsing

Jan 26, 2021
pjsipllm-pjsip-ddffe3ffb2401a66

Sudo Privilege Escalation Vulnerability (Baron Samedit)

Jan 1, 2021
denollm-deno-9e9192419f794b05

Sudo Privilege Escalation Vulnerability (Baron Samedit)

invoiceplanellm-invoiceplane-02609178a77f58a0

A vulnerability was recently discovered in the Linux utility sudo, described in CVE-2021-3156, that may allow an attacker with unprivileged local shell access on a system with sudo installed to escalate their privileges to root on the system.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/161160/Sudo-Heap-Based-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2021/Feb/42
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2021/Jan/79
ExploitMailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Feb/3
ExploitMailing ListThird Party Advisory
kc.mcafee.com / corporate/index
Broken LinkThird Party Advisory
lists.debian.org / debian-lts-announce/2021/01/msg00022.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII
Mailing ListRelease Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY
Mailing ListRelease Notes
security.gentoo.org / glsa/202101-33
Third Party Advisory
security.netapp.com / advisory/ntap-20210128-0001
Third Party Advisory
security.netapp.com / advisory/ntap-20210128-0002
Third Party Advisory
support.apple.com / kb/HT212177
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM
Third Party Advisory
beyondtrust.com / blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability
Third Party Advisory
debian.org / security/2021/dsa-4839
Third Party Advisory
kb.cert.org / vuls/id/794544
Third Party AdvisoryUS Government Resource
openwall.com / lists/oss-security/2021/01/26/3
ExploitMailing ListThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
sudo.ws / stable.html
Release Notes
synology.com / security/advisory/Synology_SA_21_02
Third Party Advisory
vicarius.io / vsociety/posts/sudoedit-pwned-cve-2021-3156
ExploitThird Party Advisory
openwall.com / lists/oss-security/2021/01/26/3
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/01/27/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/01/27/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/02/15/1
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/09/14/2
Mailing ListPatchThird Party Advisory
openwall.com / lists/oss-security/2024/01/30/6
ExploitMailing List
openwall.com / lists/oss-security/2024/01/30/8
Mailing List