Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23239

15
FAUCET Score

CVE-2021-23239 is a low-severity race condition vulnerability in the sudoedit personality of Sudo before version 1.9.5, affecting products like Debian and Fedora. A local, unprivileged user could potentially perform arbitrary directory-existence tests. With a CVSS score of 2.5, exploitation requires high attack complexity and offers limited impact, specifically low confidentiality and no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage, indicating a low current threat level.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.32CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
>= 1.9.0, < 1.9.5CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.5LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.03%
Probability of exploitation in next 30 days
EPSS Percentile
60.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0103 is in the 97th percentile among its peer group of 223 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 14127-12137Fixed in: -
microsoftpatch availablevia msrc
Product: 14128-12137Fixed in: -
microsoftpatch availablevia msrc
Product: 14129-12138Fixed in: -
microsoftpatch availablevia msrc
Product: 14130-12138Fixed in: -
microsoftpatch availablevia msrc
Product: sudo-debuginfo-1.9.5p2-2.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: -
microsoftpatch availablevia msrc
Product: sudo-1.9.5p2-2.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: -
microsoftpatch availablevia msrc
Product: sudo-debuginfo-1.9.5p2-2.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: -
microsoftpatch availablevia msrc
Product: sudo-1.9.5p2-2.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: -
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sudo-0:1.8.29-7.el8
View patch

Vendor Advisories (2)

microsoft2021-Jan/CVE-2021-23239

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

Jan 12, 2021
redhatCVE-2021-23239Low

sudo: possible directory existence test due to race condition in sudoedit

Jan 11, 2021

References

bugzilla.suse.com / show_bug.cgi
ExploitIssue TrackingThird Party Advisory
lists.debian.org / debian-lts-announce/2022/11/msg00007.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EE42Y35SMJOLONAIBNYNFC7J44UUZ2Y6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GMY4VSSBIND7VAYSN6T7XIWJRWG4GBB3
security.gentoo.org / glsa/202101-33
Third Party Advisory
security.netapp.com / advisory/ntap-20210129-0010
Third Party Advisory
sudo.ws / stable.html
Release NotesVendor Advisory