CVE-2023-42465
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Affected
- sudo project/sudo
- Source
- cve@mitre.org
References
- https://arxiv.org/abs/2309.02545Technical Description, Third Party Advisory
- https://github.com/sudo-project/sudo/commit/7873f8334c8d31031f8cfa83bd97ac6029309e4fPatch
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_15Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R4Q23NHCKCLFIHSNY6KJ27GM7FSCEVXM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ/
- https://security.gentoo.org/glsa/202401-29
- https://security.netapp.com/advisory/ntap-20240208-0002/
- https://www.openwall.com/lists/oss-security/2023/12/21/9Exploit, Mailing List
- https://www.sudo.ws/releases/changelog/Release Notes
- http://www.openwall.com/lists/oss-security/2025/09/23/2
- http://www.openwall.com/lists/oss-security/2025/09/24/6
- https://arxiv.org/abs/2309.02545Technical Description, Third Party Advisory
- https://github.com/sudo-project/sudo/commit/7873f8334c8d31031f8cfa83bd97ac6029309e4fPatch
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_15Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R4Q23NHCKCLFIHSNY6KJ27GM7FSCEVXM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R4Q23NHCKCLFIHSNY6KJ27GM7FSCEVXM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ/
- https://security.gentoo.org/glsa/202401-29
- https://security.netapp.com/advisory/ntap-20240208-0002/
- https://www.openwall.com/lists/oss-security/2023/12/21/9Exploit, Mailing List
- https://www.sudo.ws/releases/changelog/Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.