
CVE-2021-3156 (Baron Samedit) Report and Research
Author: IJ Baig
Date: July 7, 2026
1.8.2 to 1.8.31p2, and stable versions 1.9.0 to 1.9.5p1.1.9.5p1To safely analyze this vulnerability, the vulnerable Sudo version was compiled within an isolated, non-production environment.

The source code for Sudo 1.9.5p1 was downloaded and compiled locally using standard make utilities. Care was taken to run this from a local directory so it did not overwrite the host system's native, patched sudo binary.

Build Confirmation: Following compilation, the custom binary was executed to verify the correct vulnerable version was built.


plugins/sudoers/sudoers.cset_cmnd() (around line 864 in version 1.9.5p1)
Imagine you have a helper whose job is to remove escape characters (backslashes) from a list of words before putting them into a newly allocated storage box (a heap buffer). The helper blindly assumes that every backslash is always followed by a valid character, so whenever they see a backslash, they skip it and copy the next character.
However, a flaw exists in how the program handles arguments when running sudoedit -s. It allows a user to sneak in a word that ends exactly with a single backslash (\), which is followed immediately by the invisible end-of-word marker (a null terminator, \0).
When the helper's code reaches this trailing backslash, it skips it and looks at the next character—the null terminator. Instead of stopping, the if statement's logic forces the helper to skip the null terminator as well. The loop keeps going, copying whatever arbitrary, out-of-bounds memory comes next into the storage box. This continuous copying beyond the intended word length overflows the designated buffer, leading to a severe heap-based buffer overflow.
Vulnerable Code Snippet:
/* Unescape characters, skipping over backslashes */
for (to = user_args, av = NewArgv + 1; (from = *av); av++) {
while (*from) {
// VULNERABILITY: If from[0] is '\' and from[1] is '\0',
// the loop evaluates to true, increments 'from', skipping the null terminator.
if (from[0] == '\\' && !isspace((unsigned char)from[1]))
from++;
*to++ = *from++;
}
*to++ = ' ';
}
*--to = '\0';
The Sudo developers fixed this logic error in version 1.9.5p2 by adding a strict bounds check. The code now explicitly ensures that the character following the backslash is not the null terminator before attempting to unescape it.
Patch Diff:
- if (from[0] == '\\' && !isspace((unsigned char)from[1]))
+ if (from[0] == '\\' && from[1] != '\0' && !isspace((unsigned char)from[1]))
Why this fixes the root cause:
The addition of from[1] != '\0' immediately stops the out-of-bounds read. Now, if the code encounters a trailing backslash at the very end of the string (meaning from[1] is the null terminator), the if statement evaluates to false. The pointer is not incremented prematurely, the null terminator is processed correctly as the end of the string, and the loop terminates safely without overflowing the heap.
For this reproduction, the widely recognized Python exploit developed by security researcher Worawit (specifically the exploit_nss.py variant) was utilized.
Before executing the PoC, it is critical to understand its mechanics. The script does not simply crash the program; it orchestrates a highly precise manipulation of memory to gain code execution.
Here is the step-by-step breakdown of the PoC's operations:
.so). This payload is designed to execute /bin/sh as root.LC_ALL, LANG, and TZ). Because Sudo loads environment variables onto the heap at startup, the script calculates the exact sizes needed to arrange the heap in a predictable layout.sudoedit -s and passes a command-line argument ending in a single backslash. This triggers the off-by-one vulnerability discussed in Section 2, causing an out-of-bounds write.service_user struct. This struct is used by the Name Service Switch (NSS) to look up system information.service_user struct is corrupted to point to the malicious .so library compiled in Step 1. When Sudo attempts to look up user privileges, it blindly loads and executes the attacker's library, granting a root shell.First, a basic crash test was conducted to prove the vulnerability exists without weaponizing it.

Next, the full Worawit exploit_nss.py script was executed against the vulnerable binary.

To verify the official fix, the exact same PoC trigger was executed against the patched Sudo binary.
sudoedit -s '\' 2>&1 | grep -q "sudoedit:" && echo "Vulnerable" || echo "Not vulnerable"

Sudo, a standard administrative program used across our servers, contains a critical flaw in how it processes text inputs containing backslashes. By carefully sending a malformed command, an attacker with basic user access can trick the system into writing data outside of its designated memory area. This mistake allows them to completely bypass security controls and gain full, unauthorized administrative control over the machine without ever needing a password.
Challenges: One of the primary challenges was the fragility of heap manipulation. Exploit payloads targeting specific OS versions often fail on others because the underlying standard C library (glibc) manages memory chunks differently. Successfully weaponizing this vulnerability required an exact understanding of memory alignment and environment variable layouts (Heap Feng Shui) specific to the target environment.