How to fix CVE-2021-3156

Viewed 1731

sudo before v1.9.5p2 has a Heap-based buffer overflow, allowing privilege escalation to root via sudoedit -s and a command-line argument that ends with a single backslash character.

I'm wondering if it is enough to run:

sudo apt update

on a Ubuntu server to fix CVE-2021-3156?

I've been doing some reading but I haven't found any concrete answer, I guess because it is a very recent issue.

Thanks you!

3 Answers

You need to update APT's package list and then install the upgrade:

sudo apt-get update
sudo apt-get --only-upgrade install sudo

Whether your system is vulnerable or not can be checked before and after a potential fix.

Just type into a non-root shell:

$ sudoedit -s /

Doing this before updating, if you get a response starting with sudoedit like:

sudoedit: /: not a regular file

your system is vulnerable and you are doing good to update sudo as advised by @Travis Warlick.

If you get a response, which should be the case after updating or you have a recent (1.9.5p2 or higher) or old enough (prior to 1.8.2) version already, like:

usage: sudoedit [-AknS] [-r role] ...

your system is not (anymore) vulnerable in relation to CVE-2021-3156.

Affected sudo versions from stock are:

  • 1.8.2 to 1.8.31p2
  • 1.9.0 to 1.9.5p1

Version 1.9.5p2 is save.

To check your version: $ sudo --version

Grabbed those informations from here.

Here's the latest updates on this issue :

CVE-2021-3156 is a heap-overflow vulnerability in the sudo binary while parsing command line arguments. The vulnerability allows an attacker to elevate privilege to root when exploited successfully. Since it is a userland vulnerability, there is no risk of crashing the machine when attempting exploitation.

Since sudo is a very basic package this vulnerability exists on most Linux and BSD systems and action needs to be taken urgently.

In order to manually test your system if this vulnerability applies please run the following command "sudoedit -s /". If a "sudoedit:" is displayed in the output the system is vulnerable.

A "usage:..." shows that it is not vulnerable. This problem has existed since July 2011 and applies to old sudo versions like 1.8.2 to 1.8.31p2 as well as to current versions 1.9.0 until 1.9.5p1.

The current stable release of the sudo 1.9 branch is version 1.9.7p1.

I just moved my RHEL 6 to have the 1.9.7p1 and Bingo !!!

Get binary file from the following link : https://www.sudo.ws/download.html#binary

and extract/install on your OS.

That's it !!

Related