Sudo is a foundational privilege-delegation utility deployed on virtually every Unix and Linux system, making the sudo project among the most critical single-product vendors in the security landscape despite its narrow portfolio. Vulnerabilities affecting sudo frequently acquire public exploit code and have a moderate tendency toward confirmed in-the-wild exploitation, reflecting both the utility's ubiquity and the high value of privilege-escalation flaws to attackers. The recurring exposure centers on weakness classes characteristic of a setuid binary sitting at the boundary between user and kernel privilege: race conditions in shared resource handling, improper input validation and output escaping, link-following issues, and privilege-management logic errors that can permit unprivileged users to gain elevated access. Defenders should treat sudo advisories as high-priority across all Unix and Linux infrastructure; remediation typically requires coordinated patching of every affected system. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sudo Project over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2025-32463HIGH Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | Jun 30, 2025 | 7.8 | 96 | YES | YES |
CVE-2019-14287HIGH In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invok | Oct 17, 2019 | 8.8 | 84 | NO | YES |
CVE-2023-22809HIGH In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a lo | Jan 18, 2023 | 7.8 | 75 | NO | YES |
CVE-2019-18634HIGH In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in | Jan 29, 2020 | 7.8 | 48 | NO | YES |
CVE-2025-32462HIGH Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. | Jun 30, 2025 | 8.8 | 45 | NO | YES |
CVE-2017-1000367MEDIUM Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and c | Jun 5, 2017 | 6.4 | 37 | NO | YES |
CVE-2015-5602HIGH sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstr | Nov 17, 2015 | 7.2 | 35 | NO | YES |
CVE-2002-0184HIGH Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p ( | May 16, 2002 | 7.8 | 33 | NO | YES |
CVE-2026-35535HIGH In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to p | Apr 3, 2026 | 7.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sudo Project.
Media articles that mention a CVE ID that affects a product developed by Sudo Project — matched by CVE ID, not by vendor name.