Input validation error in Sudo - CVE-2023-22809
Published: January 18, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists within the sudoedit (aka -e) feature due to insufficient validation of user-supplied input passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR). The problem exists because a user-specified editor may contain a "--"
argument that defeats a protection mechanism, e.g., an EDITOR='vim --
/path/to/extra/file' value. A local user can append arbitrary entries to the list of files to process and escalate privileges on the system.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Dell Hybrid Client
EMC ECS
cflinuxfs3
PowerStore T
XtremIO X2
EMC Cloud Tiering Appliance
Amazon Linux AMI
Debian Linux
Gentoo Linux
QuTScloud
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
macOS
VMware Tanzu Application Service for VMs
Isolation Segment
Oracle Communications Diameter Signaling Router
Dell Secure Connect Gateway
Session Smart Router
IBM Spectrum Protect Plus
QVP (QVR Pro appliances)
LANTIME Operating System Firmware (LTOS)
QuTS hero
IBM Integrated Analytics System
IBM QRadar Network Packet Capture
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo (Red Hat package)
sudo-debuginfo
sudo-debugsource
sudo
sudo-devel
sudo-help
sudo (Debian package)
sudo-plugin-python-debuginfo
sudo-plugin-python
sudo-test
app-admin/sudo
redhat-release-virtualization-host (Red Hat package)
IBM Security Guardium
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Dell EMC VxRail Appliance
IBM Qradar SIEM
How to mitigate CVE-2023-22809
VMware Tanzu Application Service for VMs - addressed in versions 2.11.35, 2.12.24, 2.13.17, 3.0.7
Isolation Segment - addressed in versions 2.11.29, 2.12.19, 2.13.14, 3.0.7
IBM Integrated Analytics System - update to 1.0.31.0
EMC ECS - update to 3.7.0.6
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
sudo (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-ldap (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
QuTS hero - update to h5.0.1.2348 build 20230324
cflinuxfs3 - update to 0.351.0
sudo (Red Hat package) - addressed in versions 1.8.6p3-29.el6_10.7, 1.8.19p2-12.el7_4.3, 1.8.23-3.el7_6.3, 1.8.23-4.el7_7.4, 1.8.23-10.el7_9.3, 1.8.25p1-8.el8_1.3, 1.8.29-5.el8_2.2, 1.8.29-7.el8_4.2, 1.8.29-8.el8_6.1, 1.8.29-8.el8_7.1, 1.9.5p2-7.el9_0.2, 1.9.5p2-7.el9_1.1
sudo-debuginfo - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-debugsource - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo - addressed in versions 1.8.23-10, 1.8.29-8
sudo-devel - update to 1.8.23-10
sudo - addressed in versions 1.8.23-10.57, 1.8.23-10.59
sudo-devel - addressed in versions 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-help - update to 1.9.2-10
sudo-debugsource - update to 1.9.2-10
sudo-debuginfo - update to 1.9.2-10
sudo-devel - update to 1.9.2-10
sudo - update to 1.9.2-10
sudo (Debian package) - update to 1.9.5p2-3+deb11u1
sudo-plugin-python-debuginfo - addressed in versions 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-plugin-python - addressed in versions 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-test - update to 1.9.9-150400.4.12.1
sudo - update to 1.9.12p2
app-admin/sudo - update to 1.9.12-r1
sudo - addressed in versions 1.9.12-1.p2.fc37, 1.9.12-2.p2.fc36
VMware Tanzu Operations Manager - addressed in versions 2.10.53, 3.0.4
PowerStore T - update to 3.5.0.1-2083289
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-4.el8ev
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
QNAP QTS - update to 5.0.1.2346 20230322
Dell Secure Connect Gateway - update to 5.14.00.16
Session Smart Router - update to 6.2.3-r2
XtremIO X2 - update to 6.4.2-13
Dell EMC VxRail Appliance - update to 7.0.411
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 6
IBM Spectrum Protect Plus - update to 10.1.14
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
macOS - update to 13.4 22F66
Links to Public Exploits and PoC-codes
- Exploit #10742 - sudo 1.8.0 to 1.9.12p1 - Privilege Escalation (October 25, 2024)
- Exploit #10456 - CVE-2023-22809-Exploiter () (August 30, 2024)
- Exploit #10136 - CVE-2023-22809-sudo-POC (CVE-2023-22809 Linux Sudo) (June 28, 2024)
- Exploit #10000 - CVE-2023-22809 () (June 14, 2024)
- Exploit #9576 - CVE-2023-22809-sudoedit-privesc (A script to automate privilege escalation with CVE-2023-22809 vulnerability) (February 27, 2024)
- Exploit #9231 - CVE-2023-22809 (Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.) (August 6, 2023)
- Exploit #9155 - CVE-2023-22809 () (June 27, 2023)
- Exploit #9127 - CVE-2023-22809 (Analysis & Exploit) (June 22, 2023)
- Exploit #9083 - Sudoedit Extra Arguments Priv Esc (May 23, 2023)
- Exploit #8763 - CVE-2023-22809-sudoedit-privesc (A script to automate privilege escalation with CVE-2023-22809 vulnerability) (January 23, 2023)
External References
Related Security Bulletins
- Privilege escalation in Sudo
- Ubuntu update for sudo
- Ubuntu update for sudo
- Debian update for sudo
- Slackware Linux update for sudo
- SUSE update for sudo
- SUSE update for sudo
- SUSE update for sudo
- SUSE update for sudo
- SUSE update for sudo
- SUSE update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 7 update for sudo
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 8.6 Extended Update Support update for sudo
- Red Hat Enterprise Linux 9 update for sudo
- Red Hat Enterprise Linux 9.0 Extended Update Support update for sudo
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for sudo
- Red Hat Enterprise Linux 8.4 Extended Update Support update for sudo
- Ubuntu update for sudo
- CentOS 7 update for sudo
- Amazon Linux AMI update for sudo
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 update for redhat-release-virtualization-host and redhat-virtualization-host
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Oracle Solaris
- Privilege escalation in QNAP operating systems
- VMware Tanzu products update for Sudo
- Gentoo update for sudo
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Red Hat Enterprise Linux 7 update for sudo
- Red Hat Enterprise Linux 7.6 Advanced Update Support update for sudo
- Red Hat Enterprise Linux 7.4 Advanced Update Support update for sudo
- VMware Tanzu products update for Sudo
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Input validation error in Dell Hybrid Client
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Dell Data Protection Central
- Fedora 37 update for sudo
- Fedora 36 update for sudo
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- openEuler update for sudo
- Amazon Linux AMI update for sudo
- Multiple vulnerabilities in Dell XtremIO X2
- Anolis OS update for sudo
- Anolis OS update for sudo
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Multiple vulnerabilities in IBM Integrated Analytics System