Evidence dossier

CVE-2021-3156

CVE-2021-3156

77.994.4Priority evidence range
As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9

Normalized restatement

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

State
PUBLISHED
Published
Jan 26, 2021
Updated
Oct 21, 2025
Evidence coverage
85%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS99.30%

2026-07-18 · v2026.06.15 · percentile 99.9%

Source stateNo scored conflict

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

mitreoriginal assertion
container

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CISA KEVoriginal assertion
observed_exploitation

Sudo Heap-Based Buffer Overflow Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.992950000000; percentile 0.999340000000

Applicability

Cited product scope

Trace impact →
n/an/a
[{"status": "affected", "version": "n/a"}]unknown
Unknown vendorUnknown product
cpe:2.3:a:beyondtrust:privilege_management_for_mac:*:*:*:*:*:*:*:*; end excluding 21.1.1supported
Unknown vendorUnknown product
cpe:2.3:a:beyondtrust:privilege_management_for_unix\/linux:*:*:*:*:basic:*:*:*; end excluding 10.3.2-10supported
Unknown vendorUnknown product
cpe:2.3:a:mcafee:web_gateway:10.0.4:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:mcafee:web_gateway:8.2.17:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:mcafee:web_gateway:9.2.8:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*; start including 10.3.0.0.0; end including 10.3.0.2.1supported
Unknown vendorUnknown product
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*; start including 10.4.0.1.0; end including 10.4.0.3.1supported
Unknown vendorUnknown product
cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*; start including 7.4.0; end including 7.7.1supported
Unknown vendorUnknown product
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*; start including 1.8.2; end excluding 1.8.32supported
Unknown vendorUnknown product
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*; start including 1.9.0; end excluding 1.9.5supported
Unknown vendorUnknown product
cpe:2.3:a:sudo_project:sudo:1.9.5:-:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:sudo_project:sudo:1.9.5:patch1:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:a:synology:diskstation_manager_unified_controller:3.0:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:h:oracle:micros_compact_workstation_3:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:oracle:micros_es400:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:oracle:micros_kitchen_display_system:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:oracle:micros_workstation_5a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:oracle:micros_workstation_6:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:synology:skynas:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:oracle:micros_compact_workstation_3_firmware:310:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:oracle:micros_es400_firmware:*:*:*:*:*:*:*:*; start including 400; end including 410supported
Unknown vendorUnknown product
cpe:2.3:o:oracle:micros_kitchen_display_system_firmware:210:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:oracle:micros_workstation_5a_firmware:5a:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:oracle:micros_workstation_6_firmware:*:*:*:*:*:*:*:*; start including 610; end including 655supported
Unknown vendorUnknown product
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:synology:skynas_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*supported

Assessments

CVSS by origin

7.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.2
nvd@nist.govCVSS 2.0 · role PrimaryAV:L/AC:L/Au:N/C:C/I:C/A:C
7.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.