Heap-based buffer overflow in Sudo - CVE-2021-3156
Published: January 26, 2021 / Updated: May 18, 2025
Vulnerability identifier: #VU50040
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3156
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in sudo. A local user can pass specially crafted data to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system with root privileges.
Affected software
Sudo
Traffix SDC
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
ClevOS
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE OpenStack Cloud
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Oracle Solaris
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
TXpert Hub CoreTec 4
Tanzu Greenplum for Kubernetes
Aruba Analytics and Location Engine
Data Computing Appliance (DCA)
Disk Library for mainframe (DLm)
PowerScale OneFS
Pro 2
MICROS Workstation 5A
LANTIME Operating System Firmware (LTOS)
MICROS Kitchen Display System Hardware
MICROS Compact Workstation 3
Insight
Flex Gen 2
Pro Gen 3
Tyco AI
cockpit-ovirt (Red Hat package)
imgbased (Red Hat package)
sudo (Debian package)
sudo (Alpine package)
sssd (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
vdsm (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sudo (Ubuntu package)
sudo (Red Hat package)
sudo-debugsource
sudo
sudo-debuginfo
sudo-ldap (Ubuntu package)
sudo-devel
sudo-help
IBM Integrated Analytics System
Ansible Automation Platform
CEM Systems AC2000
Oracle Communications Performance Intelligence Center (PIC) Software
Isolation Segment
VMware Tanzu Application Service for VMs
VideoEdge
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
VMware Tanzu Operations Manager
Red Hat Virtualization Host
RSA Authentication Manager
Dell EMC NetWorker vProxy
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
Traffix SDC
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
ClevOS
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE OpenStack Cloud
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Oracle Solaris
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
TXpert Hub CoreTec 4
Tanzu Greenplum for Kubernetes
Aruba Analytics and Location Engine
Data Computing Appliance (DCA)
Disk Library for mainframe (DLm)
PowerScale OneFS
Pro 2
MICROS Workstation 5A
LANTIME Operating System Firmware (LTOS)
MICROS Kitchen Display System Hardware
MICROS Compact Workstation 3
Insight
Flex Gen 2
Pro Gen 3
Tyco AI
cockpit-ovirt (Red Hat package)
imgbased (Red Hat package)
sudo (Debian package)
sudo (Alpine package)
sssd (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
vdsm (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sudo (Ubuntu package)
sudo (Red Hat package)
sudo-debugsource
sudo
sudo-debuginfo
sudo-ldap (Ubuntu package)
sudo-devel
sudo-help
IBM Integrated Analytics System
Ansible Automation Platform
CEM Systems AC2000
Oracle Communications Performance Intelligence Center (PIC) Software
Isolation Segment
VMware Tanzu Application Service for VMs
VideoEdge
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
VMware Tanzu Operations Manager
Red Hat Virtualization Host
RSA Authentication Manager
Dell EMC NetWorker vProxy
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2021-3156
Install update from vendor's website.
Sudo - update to 1.9.5p2
Tyco AI - update to 1.3
cockpit-ovirt (Red Hat package) - update to 0.14.17-1.el8ev
IBM Integrated Analytics System - update to 1.0.31.0
Ansible Automation Platform - update to 1.2.4
imgbased (Red Hat package) - update to 1.2.16-0.1.el8ev
sudo (Debian package) - update to 1.8.27-1+deb10u3
sudo (Alpine package) - update to 1.9.5p2-r0
TXpert Hub CoreTec 4 - update to 2.3.0
sssd (Red Hat package) - update to 2.3.0-9.el8
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.13-2.el7ev, 4.4.4-1.el8ev
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.13-20210127.0.el7_9, 4.4.4-20210201.0.el8_3
vdsm (Red Hat package) - update to 4.30.51-1.el7ev
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.028, 7.02.002
CEM Systems AC2000 - update to 10.6
macOS - addressed in versions 10.14.6 18G8022, 10.15.7 19H524, 11.2.1 20D74
Insight - update to 1.4.0
sudo (Ubuntu package) - addressed in versions 1.8.3p1-1ubuntu3.10, 1.8.9p5-1ubuntu1.5+esm6, 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo (Red Hat package) - addressed in versions 1.8.6p3-29.el6_10.4, 1.8.6p7-17.el7_2.3, 1.8.6p7-23.el7_3.3, 1.8.19p2-12.el7_4.2, 1.8.23-3.el7_6.2, 1.8.23-4.el7_7.3, 1.8.23-10.el7_9.1, 1.8.25p1-8.el8_1.2, 1.8.29-5.el8_2.1, 1.8.29-6.el8_3.1
sudo-debugsource - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-debuginfo - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-ldap (Ubuntu package) - addressed in versions 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo-devel - addressed in versions 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-devel - update to 1.9.2-2
sudo - update to 1.9.2-2
sudo-debuginfo - update to 1.9.2-2
sudo-debugsource - update to 1.9.2-2
sudo-help - update to 1.9.2-2
Flex Gen 2 - update to 1.9.4
sudo - addressed in versions 1.9.5p2-1.fc32, 1.9.5p2-1.fc33
Tanzu Greenplum for Kubernetes - update to 2.0.0
Aruba Analytics and Location Engine - addressed in versions 2.1.0.4, 2.2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.29, 2.9.17, 2.10.6
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
Pro Gen 3 - update to 2.8.0
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC NetWorker vProxy - update to 4.3.0-12
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Disk Library for mainframe (DLm) - update to 5.3.0.2
VideoEdge - update to 5.7.0
Dell EMC VxRail Appliance - update to 7.0.240
RSA Authentication Manager - update to 8.5 Patch 3
Tyco AI - update to 1.3
cockpit-ovirt (Red Hat package) - update to 0.14.17-1.el8ev
IBM Integrated Analytics System - update to 1.0.31.0
Ansible Automation Platform - update to 1.2.4
imgbased (Red Hat package) - update to 1.2.16-0.1.el8ev
sudo (Debian package) - update to 1.8.27-1+deb10u3
sudo (Alpine package) - update to 1.9.5p2-r0
TXpert Hub CoreTec 4 - update to 2.3.0
sssd (Red Hat package) - update to 2.3.0-9.el8
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.13-2.el7ev, 4.4.4-1.el8ev
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.13-20210127.0.el7_9, 4.4.4-20210201.0.el8_3
vdsm (Red Hat package) - update to 4.30.51-1.el7ev
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.028, 7.02.002
CEM Systems AC2000 - update to 10.6
macOS - addressed in versions 10.14.6 18G8022, 10.15.7 19H524, 11.2.1 20D74
Insight - update to 1.4.0
sudo (Ubuntu package) - addressed in versions 1.8.3p1-1ubuntu3.10, 1.8.9p5-1ubuntu1.5+esm6, 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo (Red Hat package) - addressed in versions 1.8.6p3-29.el6_10.4, 1.8.6p7-17.el7_2.3, 1.8.6p7-23.el7_3.3, 1.8.19p2-12.el7_4.2, 1.8.23-3.el7_6.2, 1.8.23-4.el7_7.3, 1.8.23-10.el7_9.1, 1.8.25p1-8.el8_1.2, 1.8.29-5.el8_2.1, 1.8.29-6.el8_3.1
sudo-debugsource - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-debuginfo - addressed in versions 1.8.10p3-10.32.1, 1.8.10p3-10.35.1, 1.8.20p2-3.23.1, 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-ldap (Ubuntu package) - addressed in versions 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo-devel - addressed in versions 1.8.22-4.18.1, 1.8.27-4.15.1, 1.8.27-4.51.1
sudo-devel - update to 1.9.2-2
sudo - update to 1.9.2-2
sudo-debuginfo - update to 1.9.2-2
sudo-debugsource - update to 1.9.2-2
sudo-help - update to 1.9.2-2
Flex Gen 2 - update to 1.9.4
sudo - addressed in versions 1.9.5p2-1.fc32, 1.9.5p2-1.fc33
Tanzu Greenplum for Kubernetes - update to 2.0.0
Aruba Analytics and Location Engine - addressed in versions 2.1.0.4, 2.2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.29, 2.9.17, 2.10.6
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
Pro Gen 3 - update to 2.8.0
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC NetWorker vProxy - update to 4.3.0-12
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Disk Library for mainframe (DLm) - update to 5.3.0.2
VideoEdge - update to 5.7.0
Dell EMC VxRail Appliance - update to 7.0.240
RSA Authentication Manager - update to 8.5 Patch 3
Links to Public Exploits and PoC-codes
- Exploit #9068 - PE_CVE-CVE-2021-3156 (Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts) (May 14, 2023)
- Exploit #8569 - CVE-2021-3156-centos7 (利用sudo提权,只针对cnetos7) (November 3, 2022)
- Exploit #8144 - CVE-2021-3156 () (July 14, 2022)
- Exploit #7539 - CVE-2021-3156 (Script en python sobre la vulnerabilidad CVE-2021-3156) (March 27, 2022)
- Exploit #7512 - CVE-2021-3156-PoC () (March 17, 2022)
- Exploit #7296 - CVE-2021-3156 (Exploit for CVE-2021-3156) (January 30, 2022)
- Exploit #7178 - CVE-2021-3156 (复现别人家的CVEs系列) (December 15, 2021)
- Exploit #7177 - CVE-2021-3156 (CVE-2021-3156 Vagrant Lab) (December 15, 2021)
- Exploit #6937 - CVE-2021-3156 () (October 24, 2021)
- Exploit #6922 - CVE-2021-3156 (CVE-2021-3156 exploit) (October 22, 2021)
- Exploit #6913 - CVE-2021-3156 () (October 22, 2021)
- Exploit #6885 - CVE-2021-3156 () (October 14, 2021)
- Exploit #6796 - sudo-exploit (CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04) (September 27, 2021)
- Exploit #6769 - CVE-2021-3156 (sudo heap overflow to LPE, in Go) (September 19, 2021)
- Exploit #6710 - CVE-2021-3156 () (September 6, 2021)
- Exploit #6601 - CVE-2021-3156 () (August 8, 2021)
- Exploit #6556 - CVE-2021-3156 () (July 25, 2021)
- Exploit #6555 - CVE-2021-3156 (Description Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. ) (July 25, 2021)
- Exploit #6499 - docker-CVE-2021-3156 (A docker environment to research CVE-2021-3156) (July 1, 2021)
- Exploit #6489 - CVE-2021-3156 () (June 30, 2021)
- Exploit #6466 - CVE-2021-3156-Baron-Samedit (1day research effort) (June 24, 2021)
- Exploit #6459 - sudo-cve-2021 (sudo安全漏洞检测脚本,用来检查您的系统当前是否存在相关的安全漏洞。) (June 21, 2021)
- Exploit #5619 - Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1) (June 17, 2021)
- Exploit #5618 - Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2) (June 17, 2021)
- Exploit #5561 - CVE-2021-3156 () (June 13, 2021)
- Exploit #5502 - CVE-2021-3156 (CVE-2021-3156) (May 30, 2021)
- Exploit #5476 - CVE-2021-3156 (PoC for CVE-2021-3156 (sudo heap overflow)) (May 24, 2021)
- Exploit #5453 - pwnedit (CVE-2021-3156 - Sudo Baron Samedit) (May 20, 2021)
- Exploit #5450 - CVE-2021-3156-plus (CVE-2021-3156非交互式执行命令) (May 20, 2021)
- Exploit #5439 - CVE-2021-3156 () (May 18, 2021)
- Exploit #5428 - CVE-2021-3156 () (May 18, 2021)
- Exploit #5419 - CVE-2021-3156 (Root shell PoC for CVE-2021-3156) (May 18, 2021)
- Exploit #5416 - CVE-2021-3156 (Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo) (May 18, 2021)
- Exploit #5361 - Sudo Heap-Based Buffer Overflow (May 9, 2021)
- Exploit #5234 - CVE-2021-3156 (Exploit generator for sudo CVE-2021-3156) (March 22, 2021)
- Exploit #5224 - CVE-2021-3156 (Sudo Baron Samedit Exploit) (March 18, 2021)
- Exploit #5219 - Sudo-Spunk (An Exploit Utlising CVE-2021-3156 To Harvest All passwords in any Linux system with Sudo < version 1.9.5p2.) (March 18, 2021)
- Exploit #5169 - kernel-exploit-factory (Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore. ) (February 23, 2021)
- Exploit #5133 - CVE-2021-3156 (CVE-2021-3156: Sudo heap overflow exploit for Debian 10) (February 9, 2021)
- Exploit #5130 - CVE-2021-3156 (CVE-2021-3156: Sudo exploit for Debain 10) (February 9, 2021)
External References
Related Security Bulletins
- Privilege escalation in Sudo
- Amazon Linux AMI update for sudo
- Slackware Linux update for sudo
- Debian update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 8.2 update for sudo
- Red Hat Enterprise Linux 8.1 update for sudo
- Red Hat Enterprise Linux 7 update for sudo
- Red Hat Enterprise Linux 7.7 update for sudo
- Red Hat Enterprise Linux 7.6 update for sudo
- Red Hat Enterprise Linux 7.4 update for sudo
- Red Hat Enterprise Linux 7.3 update for sudo
- Red Hat Enterprise Linux 7.2 update for sudo
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for sudo
- Gentoo update for sudo
- CentOS 7 update for sudo
- Heap-based buffer overflow in sudo (Alpine package)
- Multiple vulnerabilities in Oracle Solaris
- Privilege escalation in Sudo component in F5 Traffix SDC
- Red Hat Virtualization update for redhat-virtualization-host
- Multiple vulnerabilities in Red Hat Virtualization for RHEL 8
- Multiple vulnerabilities in Apple macOS
- Multiple vulnerabilities in VMware Tanzu Products
- Privilege escalation in Johnson Controls Sensormatic Tyco AI
- Privilege escalation in Johnson Controls VideoEdge
- Heap-based buffer overflow in MICROS Workstation 6
- Heap-based buffer overflow in MICROS Workstation 5A
- Heap-based buffer overflow in MICROS Kitchen Display System Hardware
- Heap-based buffer overflow in MICROS ES400 Series
- Heap-based buffer overflow in MICROS Compact Workstation 3
- Privilege escalation in Johnson Controls Sensormatic Electronics Illustra
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Privilege escalation Johnson Controls CEM Systems AC2000
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in Oracle Communications Performance Intelligence Center (PIC) Software
- SUSE update for sudo
- SUSE update for sudo
- Ubuntu update for sudo
- Ubuntu update for sudo
- Heap-based buffer overflow in Hitachi Energy TXpert Hub CoreTec 4
- ClevOS update for IBM Cloud Object Storage Systems
- Multiple vulnerabilities in Dell NetWorker vProxy
- Privilege escalation in Dell Disk Library for mainframe (DLm)
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Privilege escalation in in Dell PowerScale OneFS
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- SUSE update for sudo
- SUSE update for sudo
- SUSE update for sudo
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for sudo
- Fedora 33 update for sudo
- Fedora 32 update for sudo
- SUSE update for sudo
- Heap-based buffer overflow in HPE Aruba Analytics and Location Engine (ALE)
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Multiple vulnerabilities in IBM Integrated Analytics System