Sudo Project / Sudo
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82474 | Sudo through 1.9.17p2 Intercept Policy Bypass via execveat | HIGH | 8.5 | Aug 29, 2026 |
| CVE-2026-35535 | sudo: Sudo: Privilege escalation due to failure in privilege drop calls | HIGH | 7.8 | Apr 3, 2026 |
| CVE-2025-32463 KEV | sudo: LPE via chroot option | CRITICAL | 9.3 | Jun 30, 2025 |
| CVE-2025-32462 | sudo: LPE via host option | HIGH | 8.8 | Jun 30, 2025 |
| CVE-2023-7090 | Sudo: improper handling of ipa_hostname leads to privilege mismanagement | HIGH | 8.8 | Dec 23, 2023 |
| CVE-2023-42465 | sudo: Targeted Corruption of Register and Stack Variables | HIGH | 7.0 | Dec 22, 2023 |
| CVE-2023-28487 | sudo: Sudo does not escape control characters in sudoreplay output | MEDIUM | 5.3 | Mar 16, 2023 |
| CVE-2023-28486 | sudo: Sudo does not escape control characters in log messages | MEDIUM | 5.3 | Mar 16, 2023 |
| CVE-2023-27320 | sudo: double free with per-command chroot sudoers rules | HIGH | 7.2 | Feb 28, 2023 |
| CVE-2023-22809 | sudo: arbitrary file write with privileges of the RunAs user | HIGH | 7.8 | Jan 18, 2023 |
| CVE-2022-43995 | sudo: heap-based overflow with very small passwords | HIGH | 7.1 | Nov 2, 2022 |
| CVE-2021-3156 KEV | sudo: Heap buffer overflow in argument parsing | HIGH | 7.8 | Jan 26, 2021 |
| CVE-2021-23240 | sudo: symbolic link attack in SELinux-enabled sudoedit | HIGH | 7.8 | Jan 12, 2021 |
| CVE-2021-23239 | sudo: possible directory existence test due to race condition in sudoedit | LOW | 2.5 | Jan 12, 2021 |
| CVE-2019-18634 | sudo: Stack based buffer overflow when pwfeedback is enabled | HIGH | 7.8 | Jan 29, 2020 |
| CVE-2019-19232 | sudo: attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user | HIGH | 7.5 | Dec 19, 2019 |
| CVE-2019-19234 | sudo: by using ! character in the shadow file instead of a password hash can access to a run as all sudoer account | HIGH | 7.5 | Dec 19, 2019 |
| CVE-2005-4890 | coreutils: tty hijacking possible in "su" via TIOCSTI ioctl | HIGH | 7.8 | Nov 4, 2019 |
| CVE-2019-18684 | sudo: privilege escalation via write access to file descriptor 3 of the sudo process | HIGH | 7.0 | Nov 4, 2019 |
| CVE-2019-14287 | sudo: Privilege escalation via 'Runas' specification with 'ALL' keyword | HIGH | 8.8 | Oct 17, 2019 |
| CVE-2016-7076 | sudo: noexec bypass via wordexp() | HIGH | 7.8 | May 29, 2018 |
| CVE-2015-8239 | sudo: Race condition when checking digests in sudoers | HIGH | 7.0 | Oct 10, 2017 |
| CVE-2017-1000368 | sudo: Privilege escalation via improper get_process_ttyname() parsing (insufficient fix for CVE-2017-1000367) | HIGH | 8.2 | Jun 5, 2017 |
| CVE-2017-1000367 | sudo: Privilege escalation in via improper get_process_ttyname() parsing | HIGH | 7.8 | Jun 5, 2017 |
| CVE-2014-9680 | sudo: unsafe handling of TZ environment variable | LOW | 3.3 | Apr 24, 2017 |
Showing 1 to 25 of 27 CVEs