sudo
Safeguard articles tagged "sudo" — guides, analysis, and best practices for software supply chain and application security.
5 articles
CVE-2021-3156: Sudo Heap-Based Buffer Overflow Vulnerability
CVE-2021-3156 affects Sudo Sudo and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-04-06.
CVE-2025-32463: Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2025-32463 affects Sudo Sudo and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-29.
A Sudo Bug Let Local Users Reach Root Without Ever Appearing in Sudoers
CVE-2025-32463 let any local user leverage sudo's --chroot option to run commands as root, bypassing the sudoers access-control model entirely.
Baron Samedit (CVE-2021-3156) Explained: The Sudo Root Overflow
CVE-2021-3156, Baron Samedit, is a heap overflow in sudo that gives any local user root and hid in plain sight for nearly a decade. Here is the root cause, a one-line test, and the patched version.
sudo -e/sudoedit privilege escalation bypass (CVE-2019-14287)
CVE-2019-14287 let sudo users bypass "run as any user except root" rules via `sudo -u#-1`, gaining full root. Here's how it worked and how to fix it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.