<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:29:29.316510+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-00364</id>
    <title>bdu:2021-00364</title>
    <updated>2026-10-03T04:29:29.826642+00:00</updated>
    <content>bdu:2021-00364</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-00364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3156</id>
    <title>Withdrawn: BELL-CVE-2021-3156 — CVE-2021-3156 does not affect BellSoft software</title>
    <updated>2026-10-03T04:29:29.826685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-063</id>
    <title>certfr-2021-avi-063 — Une vulnérabilité a été découverte dans Sudo. Elle permet à un attaquant
de provoquer une élévation de privilèges. Les…</title>
    <updated>2026-10-03T04:29:29.826704+00:00</updated>
    <content>certfr-2021-avi-063</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-sudo-privesc-jan2021-qnyqfcm</id>
    <title>cisco-sa-sudo-privesc-jan2021-qnYQfcM — Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021</title>
    <updated>2026-10-03T04:29:29.826720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the command line parameter parsing code of Sudo could allow an authenticated, local attacker to execute commands or binaries with root privileges.

The vulnerability is due to improper parsing of command line parameters that may result in a heap-based buffer overflow. An attacker could exploit this vulnerability by accessing a Unix shell on an affected device and then invoking the sudoedit command with crafted parameters or by executing a binary exploit. A successful exploit could allow the attacker to execute commands or binaries with root privileges.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM"]</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-sudo-privesc-jan2021-qnyqfcm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-07130</id>
    <title>cnvd-2021-07130</title>
    <updated>2026-10-03T04:29:29.826752+00:00</updated>
    <content>cnvd-2021-07130</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-07130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256034</id>
    <title>EUVD-2026-256034</title>
    <updated>2026-10-03T04:29:29.826764+00:00</updated>
    <content>EUVD-2026-256034</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3156</id>
    <title>fkie_cve-2021-3156</title>
    <updated>2026-10-03T04:29:29.826775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w5vh-2923-gp5c</id>
    <title>GHSA-w5vh-2923-gp5c</title>
    <updated>2026-10-03T04:29:29.826796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character:</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w5vh-2923-gp5c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3156</id>
    <title>gsd-2021-3156</title>
    <updated>2026-10-03T04:29:29.826811+00:00</updated>
    <content>gsd-2021-3156</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-119-03</id>
    <title>ICSA-21-119-03 — Johnson Controls Exacq Technologies exacqVision</title>
    <updated>2026-10-03T04:29:29.826821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product calculates or uses an incorrect maximum or minimum value that is one more or one less than the correct value.CVE-2021-3156 has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-119-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1002</id>
    <title>OESA-2021-1002 — sudo security update</title>
    <updated>2026-10-03T04:29:29.826839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: sudo, openEuler:20.03-LTS-SP1: sudo</p>
<p>A flaw was found in sudo. A heap-based buffer overflow was found in the way sudo parses command line arguments. This flaw is exploitable by any local user (normal users and system users, sudoers and non-sudoers), without authentication (i.e., the attacker does not need to know the user's password). Successful exploitation of this flaw could lead to privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2021-3156)\r\n\r\n
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.(CVE-2021-23239)\r\n\r\n
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.(CVE-2021-23240)\r\n\r\n</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0169-1</id>
    <title>openSUSE-SU-2021:0169-1 — Security update for sudo</title>
    <updated>2026-10-03T04:29:29.826869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0169-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0219</id>
    <title>RHSA-2021:0219 — Red Hat Security Advisory: sudo security update</title>
    <updated>2026-10-03T04:29:29.826894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo: Heap buffer overflow in argument parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:0225-1</id>
    <title>SUSE-SU-2021:0225-1 — Security update for sudo</title>
    <updated>2026-10-03T04:29:29.826911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:0225-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3156</id>
    <title>UBUNTU-CVE-2021-3156</title>
    <updated>2026-10-03T04:29:29.826927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo</p>
<p>Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-011</id>
    <title>VDE-2021-011 — TRUMPF Laser GmbH: TruControl 2.14.0 to 3.14.0 affected by recent sudo vulnerability</title>
    <updated>2026-10-03T04:29:29.826950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0066</id>
    <title>WID-SEC-W-2023-0066 — sudo: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-03T04:29:29.826966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0066"/>
  </entry>
</feed>
