CVE-2021-23239

Updated: 2026-02-08 04:36:18.561525

Description:

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x LOW 1.9
CVSS Version 3.x LOW 2.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU sudo 1.9.5p2 2.5 LOW Ignored 2023-11-08 04:07:50 This flaw is local-only and requires a high‑complexity race during sudoedit of a non‑existent fi...
CentOS 6 ELS sudo 1.8.6p3 2.5 LOW Ignored 2021-11-02 14:03:19 Ignored due to low severity
CentOS 7 ELS sudo 1.8.23 2.5 LOW Ignored 2023-09-19 09:30:11 Ignored due to low severity
CentOS 8.4 ELS sudo 1.8.29-7 2.5 LOW Already Fixed 2023-10-30 11:22:07
CentOS 8.5 ELS sudo 1.8.29-7 2.5 LOW Already Fixed 2023-10-30 11:22:07
CloudLinux 6 ELS sudo 1.8.6p3 2.5 LOW Ignored 2021-11-02 14:03:19 Ignored due to low severity
Debian 10 ELS sudo 1.8.27 2.5 LOW Ignored 2025-10-11 00:18:54 Ignored due to low severity
Oracle Linux 6 ELS sudo 1.8.6p3 2.5 LOW Ignored 2021-11-02 14:03:19 Ignored due to low severity
Ubuntu 16.04 ELS sudo 1.8.16 2.5 LOW Not Vulnerable 2021-11-02 14:03:19
Ubuntu 18.04 ELS sudo 1.8.21 2.5 LOW Already Fixed 2023-06-02 09:09:51