Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-3156-Baron-Samedit — 1day research effort | Kitploit
Tools/GitHubGitHub/kernelzeroday/cve-2021-3156-baron-samedit
Vulnerability AnalysisExploitationDebuggersFuzzingLearning & EducationBinary Exploitation
GitHubkernelzeroday/cve-2021-3156-baron-samedit

CVE-2021-3156-Baron-Samedit

1day research effort

View Repository
185145 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-3156-Baron-Samedit

This repo contains my work on clumsily implementing a public 1day exploit for the sudo bug. Wish me luck.

If you would like to help please feel free.

Compile the provided src/sudo sudoedit has been modified to use AFL harness to get input from STDIN

AFL Fuzzy loop crash test cases discovered so far, check these out:

-rw------- 1 root root   309 Jan 28 03:31 id:000000,sig:11,src:000024,time:335,op:havoc,rep:2
-rw------- 1 root root   309 Jan 28 03:31 id:000001,sig:06,src:000024,time:1419,op:havoc,rep:4
-rw------- 1 root root   278 Jan 28 03:31 id:000002,sig:06,src:000024,time:2545,op:havoc,rep:8
-rw------- 1 root root   300 Jan 28 03:31 id:000003,sig:11,src:000024,time:5812,op:havoc,rep:4
-rw------- 1 root root   309 Jan 28 03:31 id:000004,sig:11,src:000024,time:7063,op:havoc,rep:8
-rw------- 1 root root   296 Jan 28 03:31 id:000005,sig:11,src:000024,time:8231,op:havoc,rep:8
-rw------- 1 root root   309 Jan 28 03:31 id:000006,sig:11,src:000024,time:8395,op:havoc,rep:2
-rw------- 1 root root   310 Jan 28 03:31 id:000007,sig:11,src:000024,time:9048,op:havoc,rep:8
-rw------- 1 root root   277 Jan 28 03:31 id:000008,sig:11,src:000024,time:9305,op:havoc,rep:16
-rw------- 1 root root   281 Jan 28 03:31 id:000009,sig:06,src:000024,time:11059,op:havoc,rep:2
-rw------- 1 root root   232 Jan 28 03:31 id:000010,sig:11,src:000024,time:13883,op:havoc,rep:4
-rw------- 1 root root   304 Jan 28 03:31 id:000011,sig:11,src:000024,time:17245,op:havoc,rep:8
-rw------- 1 root root   265 Jan 28 03:31 id:000012,sig:06,src:000024,time:18928,op:havoc,rep:8
-rw------- 1 root root   309 Jan 28 03:31 id:000013,sig:11,src:000024,time:21131,op:havoc,rep:8
-rw------- 1 root root   309 Jan 28 03:31 id:000014,sig:09,src:000024,time:29628,op:havoc,rep:4
-rw------- 1 root root   306 Jan 28 03:32 id:000015,sig:11,src:000024,time:60593,op:havoc,rep:8
-rw------- 1 root root   284 Jan 28 03:32 id:000016,sig:06,src:000024,time:65998,op:havoc,rep:16
-rw------- 1 root root 91053 Jan 28 03:39 id:000017,sig:09,src:000026+000018,time:518485,op:splice,rep:8
-rw------- 1 root root   318 Jan 28 03:39 id:000018,sig:11,src:000026+000045,time:520493,op:splice,rep:2
-rw------- 1 root root 65399 Jan 28 03:42 id:000019,sig:06,src:000012,time:678458,op:havoc,rep:16
-rw------- 1 root root 65441 Jan 28 04:33 id:000020,sig:06,src:000009,time:3762442,op:havoc,rep:16
-rw------- 1 root root   303 Jan 28 04:44 id:000021,sig:11,src:000025+000034,time:4377085,op:splice,rep:4
-rw------- 1 root root 91045 Jan 28 04:46 id:000022,sig:06,src:000019+000058,time:4538775,op:splice,rep:16
-rw------- 1 root root   296 Jan 28 05:14 id:000023,sig:06,src:000051,time:6173954,op:havoc,rep:16
-rw------- 1 root root   279 Jan 28 06:10 id:000024,sig:11,src:000023+000037,time:9549571,op:splice,rep:4

sig:11 means Segmentation Fault which is what we want. Signal 06 is SIGABRT which they gave us to start with.

load up the compiled sudoedit (make sure it has effective uid 0, run gdb as root) # gdb /usr/local/bin/sudoedit

Load crash case from src/afl3/out/default/crashes: (note: this is the first sigsegv i found, its not a very good one, this id:000008 can be found in crashes_old)

gef➤  r < id:000008*

[ Legend: Modified register | Code | Heap | Stack | String ]
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── registers ────
$rax   : 0x414196c9adb30e58
$rbx   : 0x4141414141414140 ("@AAAAAAA"?)
$rcx   : 0x000055886c706010  →  0x0000000000000007
$rdx   : 0x4141414141414148 ("HAAAAAAA"?)
$rsp   : 0x00007fffdfe911d0  →  0x00007fb17cea12d0  →  "<- %s @ %s:%d := %s"
$rbp   : 0x00007fb17ccceb80  →  0x0000000000000000
$rsi   : 0x000055886c71cca0  →  0x4141414141414180
$rdi   : 0x00007fb17ccceb80  →  0x0000000000000000
$rip   : 0x00007fb17cb96a79  →  <_int_free+409> mov rax, QWORD PTR [r13+0x8]
$r8    : 0x7
$r9    : 0x1
$r10   : 0xfffffffffffff1ed
$r11   : 0x5
$r12   : 0x000055886c71cca0  →  0x4141414141414180
$r13   : 0x414196c9adb30de0
$r14   : 0x00007fb17cccf578  →  0x000055886c71ccb0  →  "AAAAAAAAAAAAAAAAAAAAAAAAARAAFAAAAAAAAAAAAAAAAAAAAA[...]"
$r15   : 0x00007fffdfe91290  →  0x00007fb17cc9bb5f  →  0x636d656d5f5f0043 ("C"?)
$eflags: [zero CARRY PARITY ADJUST SIGN trap INTERRUPT direction overflow RESUME virtualx86 identification]
$cs: 0x0033 $ss: 0x002b $ds: 0x0000 $es: 0x0000 $fs: 0x0000 $gs: 0x0000
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── stack ────
0x00007fffdfe911d0│+0x0000: 0x00007fb17cea12d0  →  "<- %s @ %s:%d := %s"	 ← $rsp
0x00007fffdfe911d8│+0x0008: 0x000055886c70e880  →  0x0000000000000043 ("C"?)
0x00007fffdfe911e0│+0x0010: 0x0000000000000000
0x00007fffdfe911e8│+0x0018: 0x000000017ce94e8e
0x00007fffdfe911f0│+0x0020: 0x0000000000000000
0x00007fffdfe911f8│+0x0028: 0x00007fb17cb416bb  →  <new_composite_name+203> test eax, eax
0x00007fffdfe91200│+0x0030: 0x00007fffdfe91290  →  0x00007fb17cc9bb5f  →  0x636d656d5f5f0043 ("C"?)
0x00007fffdfe91208│+0x0038: 0xdfb8629d88483900
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── code:x86:64 ────
   0x7fb17cb96a69 <_int_free+393>  je     0x7fb17cb97018 <_int_free+1848>
   0x7fb17cb96a6f <_int_free+399>  test   BYTE PTR [rbp+0x4], 0x2
   0x7fb17cb96a73 <_int_free+403>  je     0x7fb17cb97028 <_int_free+1864>
 → 0x7fb17cb96a79 <_int_free+409>  mov    rax, QWORD PTR [r13+0x8]
   0x7fb17cb96a7d <_int_free+413>  test   al, 0x1
   0x7fb17cb96a7f <_int_free+415>  je     0x7fb17cb97050 <_int_free+1904>
   0x7fb17cb96a85 <_int_free+421>  mov    r14, rax
   0x7fb17cb96a88 <_int_free+424>  and    r14, 0xfffffffffffffff8
   0x7fb17cb96a8c <_int_free+428>  cmp    rax, 0x10
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── threads ────
[#0] Id 1, Name: "sudoedit", stopped 0x7fb17cb96a79 in _int_free (), reason: SIGSEGV
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── trace ────
[#0] 0x7fb17cb96a79 → _int_free(av=0x7fb17ccceb80 <main_arena>, p=0x55886c71cca0, have_lock=<optimized out>)
[#1] 0x7fb17cb41e5c → setname(name=0x7fb17cc9bb5f <_nl_C_name> "C", category=0xb)
[#2] 0x7fb17cb41e5c → __GI_setlocale(category=0xb, locale=<optimized out>)
[#3] 0x7fb17c70cc59 → sudoers_setlocale(locale_type=0x1, prev_locale=<optimized out>)
[#4] 0x7fb17c722336 → sudoers_policy_main(argc=<optimized out>, argv=<optimized out>, pwflag=0x0, env_add=<optimized out>, verbose=0x0, closure=0x7fffdfe93488)
[#5] 0x7fb17c71d65e → sudoers_policy_check(argc=0x7, argv=0x55886c709570, env_add=0x0, command_infop=0x7fffdfe93520, argv_out=0x7fffdfe93558, user_env_out=0x7fffdfe93540, errstr=0x7fffdfe93620)
[#6] 0x55886b1185db → policy_check(argc=0x7, argv=0x55886c709570, env_add=0x0, command_info=0x7fffdfe93520, argv_out=0x7fffdfe93558, user_env_out=0x7fffdfe93540)
[#7] 0x55886b1185db → main(argc=<optimized out>, argv=<optimized out>, envp=0x7fffdfe94758)
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
gef➤
Download Tool