Privilege Escalation Vulnerability Hits Linux-Based Systems – Patch Now!

What is CVE-2021-3156 – “Baron Samedit”

High-severity vulnerability, also known as Baron Samedit with CVE-2021-3156 ID, was discovered. The vulnerability, which exists in versions prior to 1.9.5p2 of Sudo, allows unauthorized privilege escalation on Linux-based systems.

Why It Matters

  • Discovered by Low-Privileged Users
    Default user rights-based hackers can utilize this bug to gain root-level privileges, despite not being listed in the sudoers file.
  • Buffer Overflow Exploit
    The bug converts a pre-existing buffer overflow vulnerability in Sudo into an attack vector for bypassing security configurations.
  • Widespread Impact
    Since Sudo is pre-installed on many Linux distributions, this bug’s impact will be far-reaching and target critical infrastructure, business servers, and commercial networks

What You Should Do

  • Update Immediately:
    Update to Sudo 1.9.5p2 or higher, which contains the official patch.
  • Strengthen Password Policies:
    Make sure there are good password policies and good authentication.
  • Apply Security Patches on a Regular Basis:
    Make sure your systems and applications are patched with the latest patches to defend against known vulnerabilities.

FAQs

Q1: Who is CVE-2021-3156 affecting?
Any Sudo release prior to 1.9.5p2, especially any default Linux installs.

Q2: Is the bug exploitable by non-sudo users?
Yes. The bug grants root access even to non-sudo users.

Conclusion: Patch Without Delay

Pakistan Telecommunication Authority (PTA) advises all IT departments and organizations to patch immediately. Patching the vulnerability will never lead to full system compromise, data disclosure, or drastic operational impact.