Double Free in Sudo - CVE-2023-27320

 

Double Free in Sudo - CVE-2023-27320

Published: March 2, 2023


Vulnerability identifier: #VU72719
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27320
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when matching a sudoers rule that contains a per-command chroot directive (CHROOT=dir). A local user can trigger a double free error and execute arbitrary code with elevated privileges.



Affected software

Sudo
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Linux Enterprise Micro
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
LANTIME Operating System Firmware (LTOS)
ObjectScale
sudo
sudo-debuginfo
sudo-debugsource
sudo-devel
sudo-help
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-plugin-python
sudo-plugin-python-debuginfo
sudo-test
app-admin/sudo
VMware Tanzu Operations Manager

How to mitigate CVE-2023-27320

Install updates from vendor's website.

Sudo - update to 1.9.13p2
LANTIME Operating System Firmware (LTOS) - update to 7.06.014
ObjectScale - update to 1.4.0
sudo - update to 1.8.23-10.59
sudo-debuginfo - update to 1.9.8p2-10
sudo-debugsource - update to 1.9.8p2-10
sudo-devel - update to 1.9.8p2-10
sudo - update to 1.9.8p2-10
sudo-help - update to 1.9.8p2-10
sudo (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-ldap (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-plugin-python - update to 1.9.9-150400.4.26.1
sudo-devel - update to 1.9.9-150400.4.26.1
sudo-plugin-python-debuginfo - update to 1.9.9-150400.4.26.1
sudo-test - update to 1.9.9-150400.4.26.1
sudo-debugsource - update to 1.9.9-150400.4.26.1
sudo - update to 1.9.9-150400.4.26.1
sudo-debuginfo - update to 1.9.9-150400.4.26.1
app-admin/sudo - update to 1.9.12-r1
sudo - addressed in versions 1.9.13-1.p2.fc36, 1.9.13-1.p2.fc37, 1.9.13-1.p2.fc38
VMware Tanzu Operations Manager - update to 3.0.5

External References

Related Security Bulletins