PT-2023-8553 · Sudo+7 · Sudo+7

Published

2023-09-05

·

Updated

2025-11-05

·

CVE-2023-42465

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sudo versions prior to 1.9.15
Description The issue is related to the authentication procedure in Sudo, which might allow row hammer attacks for authentication bypass or privilege escalation. This is because the application logic sometimes relies on not equaling an error value instead of equaling a success value, and the values do not resist flips of a single bit. The vulnerability is associated with weaknesses in the authentication procedure, potentially allowing an attacker to escalate their privileges.
Recommendations For Sudo versions prior to 1.9.15, update to version 1.9.15 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation. Avoid using the vulnerable authentication mechanism until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2024:0811
ALT-PU-2023-7026
ALT-PU-2023-7648
ALT-PU-2023-8393
ALT-PU-2024-7909
AZL-32227
BDU:2024-01160
CESA-2024_0811
CVE-2023-42465
ECHO-F224-90BF-BCD4
INFSA-2024_0811
OESA-2024-1071
OPENSUSE-SU-2024:13490-1
OPENSUSE-SU-2024_0794-1
OPENSUSE-SU-2024_0834-1
OPENSUSE-SU-2024_0876-1
RHSA-2024:0811
RHSA-2024_0811
SUSE-SU-2024:0794-1
SUSE-SU-2024:0794-2
SUSE-SU-2024:0795-1
SUSE-SU-2024:0795-2
SUSE-SU-2024:0796-1
SUSE-SU-2024:0796-2
SUSE-SU-2024:0797-1
SUSE-SU-2024:0797-2
SUSE-SU-2024:0834-1
SUSE-SU-2024:0876-1
SUSE-SU-2024:0876-2
SUSE-SU-2024:0877-1
SUSE-SU-2024:0889-1
SUSE-SU-2024:0890-1
SUSE-SU-2024_0794-1
SUSE-SU-2024_0794-2
SUSE-SU-2024_0795-1
SUSE-SU-2024_0795-2
SUSE-SU-2024_0796-1
SUSE-SU-2024_0796-2
SUSE-SU-2024_0797-1
SUSE-SU-2024_0797-2
SUSE-SU-2024_0834-1
SUSE-SU-2024_0876-1
SUSE-SU-2024_0877-1
SUSE-SU-2024_0889-1
SUSE-SU-2024_0890-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Red Hat
Red Os
Sudo
Suse