CVE-2021-3156
Synology · exploited in the wild
- Published
- 26 January 2021
- Last modified
- 17 June 2026
- CVSS
- 7.8 v3.1
- Severity
- high
- EPSS
- >99.9% (100th pct)
- CISA KEV
- Added 6 April 2022 KEV
- NVD status
- Analyzed
- Weaknesses
- CWE-193
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Exploitation
Added to the CISA Known Exploited Vulnerabilities catalogue on 6 April 2022, with a remediation due date of 27 April 2022 for US federal civilian agencies. CISA records no known ransomware campaign use.
Required action as published by CISA: Apply updates per vendor instructions.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| VS960HD | Synology | unknown | < 2.2.3-1505, < 2.3.6-1720 |
References
Vendor advisory and patch
- http://www.openwall.com/lists/oss-security/2021/09/14/2
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- http://www.openwall.com/lists/oss-security/2021/09/14/2
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html exploit
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html exploit
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html exploit
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html exploit
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html exploit
- http://seclists.org/fulldisclosure/2021/Feb/42 third-party
- http://seclists.org/fulldisclosure/2021/Jan/79 exploit
- http://seclists.org/fulldisclosure/2024/Feb/3 exploit
- http://www.openwall.com/lists/oss-security/2021/01/26/3 exploit
- http://www.openwall.com/lists/oss-security/2021/01/27/1 third-party
- http://www.openwall.com/lists/oss-security/2021/01/27/2 third-party
- http://www.openwall.com/lists/oss-security/2021/02/15/1 exploit
- http://www.openwall.com/lists/oss-security/2024/01/30/6 exploit
- http://www.openwall.com/lists/oss-security/2024/01/30/8
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348 third-party
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html third-party
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/
- https://security.gentoo.org/glsa/202101-33 third-party
- https://security.netapp.com/advisory/ntap-20210128-0001/ third-party
- https://security.netapp.com/advisory/ntap-20210128-0002/ third-party
- https://support.apple.com/kb/HT212177 third-party
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM third-party
- https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability third-party
- https://www.debian.org/security/2021/dsa-4839 third-party
- https://www.kb.cert.org/vuls/id/794544 third-party
- https://www.openwall.com/lists/oss-security/2021/01/26/3 exploit
- https://www.sudo.ws/stable.html#1.9.5p2
- https://www.synology.com/security/advisory/Synology_SA_21_02 third-party
- https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156 exploit
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html exploit
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html exploit
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html exploit
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html exploit
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html exploit
- http://seclists.org/fulldisclosure/2021/Feb/42 third-party
- http://seclists.org/fulldisclosure/2021/Jan/79 exploit
- http://seclists.org/fulldisclosure/2024/Feb/3 exploit
- http://www.openwall.com/lists/oss-security/2021/01/26/3 exploit
- http://www.openwall.com/lists/oss-security/2021/01/27/1 third-party
- http://www.openwall.com/lists/oss-security/2021/01/27/2 third-party
- http://www.openwall.com/lists/oss-security/2021/02/15/1 exploit
- http://www.openwall.com/lists/oss-security/2024/01/30/6 exploit
- http://www.openwall.com/lists/oss-security/2024/01/30/8
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348 third-party
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html third-party
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/
- https://security.gentoo.org/glsa/202101-33 third-party
- https://security.netapp.com/advisory/ntap-20210128-0001/ third-party
- https://security.netapp.com/advisory/ntap-20210128-0002/ third-party
- https://support.apple.com/kb/HT212177 third-party
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM third-party
- https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability third-party
- https://www.debian.org/security/2021/dsa-4839 third-party
- https://www.kb.cert.org/vuls/id/794544 third-party
- https://www.openwall.com/lists/oss-security/2021/01/26/3 exploit
- https://www.sudo.ws/stable.html#1.9.5p2
- https://www.synology.com/security/advisory/Synology_SA_21_02 third-party
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3156 government
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.