Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-27320

25
FAUCET Score

CVE-2023-27320 is a double free vulnerability in the per-command chroot feature of Sudo versions prior to 1.9.13p2, affecting Fedora and Sudo Project distributions. This high-severity vulnerability (CVSS 7.2) allows an authenticated attacker to achieve high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.9.8, < 1.9.13CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
1.9.13CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.13:-:*:*:*:*:*:*
1.9.13CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.13:p1:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.66%
Probability of exploitation in next 30 days
EPSS Percentile
74.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0166 is in the 68th percentile among its peer group of 5,538 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: cm1 sudo 1.9.13p3-1 on CBL Mariner 1.0Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: cbl2 sudo 1.9.13p3-1 on CBL Mariner 2.0Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: 17926-16820Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: 17937-16823Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.9.13p3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.9.13p3-1

Vendor Advisories (3)

microsoft2023-Mar/CVE-2023-27320

CVE-2023-27320

Mar 14, 2023
redhatCVE-2023-27320Moderate

sudo: double free with per-command chroot sudoers rules

Feb 28, 2023
microsoft2023-Feb/CVE-2023-27320Important

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Feb 14, 2023

References

lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU
security.gentoo.org / glsa/202309-12
Third Party Advisory
security.netapp.com / advisory/ntap-20230413-0009
Third Party Advisory
openwall.com / lists/oss-security/2023/02/28/1
ExploitMailing ListThird Party Advisory
sudo.ws / releases/stable
Release Notes
openwall.com / lists/oss-security/2023/03/01/8
Mailing ListThird Party Advisory