Double Free in Sudo - CVE-2023-27320
Published: March 2, 2023
Vulnerability identifier: #VU72719
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27320
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when matching a sudoers rule that contains a per-command chroot directive (CHROOT=dir). A local user can trigger a double free error and execute arbitrary code with elevated privileges.
Affected software
Sudo
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Linux Enterprise Micro
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
LANTIME Operating System Firmware (LTOS)
ObjectScale
sudo
sudo-debuginfo
sudo-debugsource
sudo-devel
sudo-help
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-plugin-python
sudo-plugin-python-debuginfo
sudo-test
app-admin/sudo
VMware Tanzu Operations Manager
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Linux Enterprise Micro
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
LANTIME Operating System Firmware (LTOS)
ObjectScale
sudo
sudo-debuginfo
sudo-debugsource
sudo-devel
sudo-help
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-plugin-python
sudo-plugin-python-debuginfo
sudo-test
app-admin/sudo
VMware Tanzu Operations Manager
How to mitigate CVE-2023-27320
Install updates from vendor's website.
Sudo - update to 1.9.13p2
LANTIME Operating System Firmware (LTOS) - update to 7.06.014
ObjectScale - update to 1.4.0
sudo - update to 1.8.23-10.59
sudo-debuginfo - update to 1.9.8p2-10
sudo-debugsource - update to 1.9.8p2-10
sudo-devel - update to 1.9.8p2-10
sudo - update to 1.9.8p2-10
sudo-help - update to 1.9.8p2-10
sudo (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-ldap (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-plugin-python - update to 1.9.9-150400.4.26.1
sudo-devel - update to 1.9.9-150400.4.26.1
sudo-plugin-python-debuginfo - update to 1.9.9-150400.4.26.1
sudo-test - update to 1.9.9-150400.4.26.1
sudo-debugsource - update to 1.9.9-150400.4.26.1
sudo - update to 1.9.9-150400.4.26.1
sudo-debuginfo - update to 1.9.9-150400.4.26.1
app-admin/sudo - update to 1.9.12-r1
sudo - addressed in versions 1.9.13-1.p2.fc36, 1.9.13-1.p2.fc37, 1.9.13-1.p2.fc38
VMware Tanzu Operations Manager - update to 3.0.5
LANTIME Operating System Firmware (LTOS) - update to 7.06.014
ObjectScale - update to 1.4.0
sudo - update to 1.8.23-10.59
sudo-debuginfo - update to 1.9.8p2-10
sudo-debugsource - update to 1.9.8p2-10
sudo-devel - update to 1.9.8p2-10
sudo - update to 1.9.8p2-10
sudo-help - update to 1.9.8p2-10
sudo (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-ldap (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.3, 1.9.11p3-1ubuntu1.2
sudo-plugin-python - update to 1.9.9-150400.4.26.1
sudo-devel - update to 1.9.9-150400.4.26.1
sudo-plugin-python-debuginfo - update to 1.9.9-150400.4.26.1
sudo-test - update to 1.9.9-150400.4.26.1
sudo-debugsource - update to 1.9.9-150400.4.26.1
sudo - update to 1.9.9-150400.4.26.1
sudo-debuginfo - update to 1.9.9-150400.4.26.1
app-admin/sudo - update to 1.9.12-r1
sudo - addressed in versions 1.9.13-1.p2.fc36, 1.9.13-1.p2.fc37, 1.9.13-1.p2.fc38
VMware Tanzu Operations Manager - update to 3.0.5
External References
Related Security Bulletins
- Privilege escalation in Sudo
- Ubuntu update for sudo
- SUSE update for sudo
- VMware Tanzu products update for Sudo
- Multiple vulnerabilities in Oracle Solaris third-party software
- Fedora 38 update for sudo
- Fedora 37 update for sudo
- Fedora 36 update for sudo
- Gentoo update for sudo
- openEuler 22.03 LTS SP1 update for sudo
- openEuler 22.03 LTS update for sudo
- Amazon Linux AMI update for sudo
- Amazon Linux AMI update for sudo
- Multiple vulnerabilities in Dell ObjectScale
- Meinberg LANTIME firmware update for third-party components (May 2023)