CVE-2021-3156 — Baron Samedit
Heap-Based Buffer Overflow in sudo → Local Privilege Escalation
ITSOLERA Cybersecurity Department | Red Team Internship 2026
██████╗ █████╗ ██████╗ ██████╗ ███╗ ██╗ ███████╗ █████╗ ███╗ ███╗███████╗██████╗ ██╗████████╗
██╔══██╗██╔══██╗██╔══██╗██╔═══██╗████╗ ██║ ██╔════╝██╔══██╗████╗ ████║██╔════╝██╔══██╗██║╚══██╔══╝
██████╔╝███████║██████╔╝██║ ██║██╔██╗ ██║ ███████╗███████║██╔████╔██║█████╗ ██║ ██║██║ ██║
██╔══██╗██╔══██║██╔══██╗██║ ██║██║╚██╗██║ ╚════██║██╔══██║██║╚██╔╝██║██╔══╝ ██║ ██║██║ ██║
██████╔╝██║ ██║██║ ██║╚██████╔╝██║ ╚████║ ███████║██║ ██║██║ ╚═╝ ██║███████╗██████╔╝██║ ██║
╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═══╝ ╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═════╝ ╚═╝ ╚═╝
⚠️ FOR EDUCATIONAL / ISOLATED LAB USE ONLY
All testing must be performed exclusively inside the Docker lab container.
Never run against real, production, or shared systems.
Table of Contents
- CVE Overview
- What Makes This CVE Special
- Project Structure
- Team Deliverables
- Quick Start
- How the Exploit Works
- Vulnerability Canary Test
- exploit.py Usage
- Lab Reset & Snapshot
- Patched vs Vulnerable Comparison
- References
CVE Overview
| Property | Value |
|---|
| CVE ID | CVE-2021-3156 |
| Nickname | Baron Samedit |
| Type | Heap-Based Buffer Overflow → Local Privilege Escalation |
| Component | sudo — Linux privilege utility (set_cmnd() in src/sudo.c) |
| CVSS v3 Score | 7.8 High |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Vulnerable Versions | sudo 1.8.2 – 1.8.31p2 and 1.9.0 – 1.9.5p1 |
| Patched Versions | sudo 1.9.5p2 (1.9 branch) / sudo 1.8.32 (1.8 branch) |
| Lab Target Version | sudo 1.8.31 on Ubuntu 20.04 |
| Patch KB / Advisory | SA: https://www.sudo.ws/security/advisories/unescape_overflow/ |
| Discovered By | Qualys Research Team |
| Disclosed | 2021-01-26 |
| In Wild Since (code) | ~2011-07-09 (sudo 1.8.2) — ~10 years undetected |
| Auth Required | Local user only — NO sudo permissions needed |
What Makes This CVE Special
| Property | CVE-2021-3156 | Typical Sudo LPE |
|---|
| Requires sudoers entry | ❌ No | ✅ Yes |
| Requires sudo group membership | ❌ No | ✅ Yes |
| Requires any prior sudo access | ❌ No | ✅ Yes |
| Works from brand-new user account | ✅ Yes | ❌ No |
| Exploits permission system | ❌ Bypasses entirely | ✅ Abuses it |
| Attack surface | Argument parser (pre-auth) | Permission check |
Key insight: The overflow happens in set_cmnd() — the function that
parses arguments — which runs before sudo ever consults /etc/sudoers.
An account created 10 seconds ago with zero permissions can exploit this.
Project Structure
CVE-2021-3156-Project/
│
├── README.md ← you are here
│
├── lab/ ← Member 1: Lab Environment
│ ├── Dockerfile ← Ubuntu 20.04 + sudo 1.8.31 (pinned)
│ ├── docker-compose.yml ← vulnerable target + patched reference
│ ├── evidence_helper.sh ← pre/post-exploit state capture
│ ├── SETUP.md ← step-by-step VM/Docker guide
│ └── config_notes.md ← CVE conditions & container details
│
├── exploit/ ← Member 2: Exploit Development
│ ├── exploit.py ← Python LPE framework + canary test
│ └── payloads.txt ← heap overflow research notes
│
├── docs/ ← Member 3: Research & Documentation
│ ├── root_cause_analysis.md ← set_cmnd() deep dive + off-by-one
│ ├── references.md ← all sources, PoCs, CWE mapping
│ └── mitigation.md ← sudo upgrade + hardening checklist
│
├── proof/ ← Member 4: Evidence Collection
│ ├── screenshots/ ← exploitation screenshots
│ └── terminal_logs.txt ← command output template + logs
│
└── report/
└── CVE-2021-3156_Report.docx ← Member 4: Final professional report
Team Deliverables
Member 1 — Lab Environment & CVE Verification
| File | Description |
|---|
lab/Dockerfile | Ubuntu 20.04 with sudo 1.8.31 pinned (vulnerable); Python 3 installed; labuser account with NO sudo access |
lab/docker-compose.yml | Orchestrates vulnerable target + patched Ubuntu 22.04 reference container |
lab/evidence_helper.sh | Bash script to capture system state (user, sudo version, canary) before/after exploit |
lab/SETUP.md | Step-by-step: build → start → enter → verify sudo version → run canary → snapshot |
lab/config_notes.md | Explains why no misconfig needed, Docker security settings, credential reference |
Member 2 — Exploit Development (PoC Script)
| File | Description |
|---|
exploit/exploit.py | Full Python framework: check_platform(), check_sudo_version(), run_canary_test(), get_system_info() + three exploit TODO stubs (select_heap_strategy, build_overflow_argument, trigger_overflow_and_escalate) with detailed references to blasty/worawit PoCs |
exploit/payloads.txt | Heap overflow concepts, COMPRESSION_TRANSFORM equivalent (argument structure), three heap strategies, failed attempt log template, detection signatures |
Note: Working kernel/heap exploit code is not included per ethical guidelines.
The exploit.py TODO stubs reference https://github.com/blasty/CVE-2021-3156
and https://github.com/worawit/CVE-2021-3156 as the authoritative public PoCs
for your team to study and integrate.
Member 3 — Root Cause Analysis & Research
| File | Description |
|---|
docs/root_cause_analysis.md | Detailed: set_cmnd() size vs copy mismatch, off-by-one with code examples, patch diff, exploit chain, CVSS 7.8 metric-by-metric, 10-year timeline, distribution impact table |
docs/references.md | Qualys advisory, MITRE, NVD, sudo project, blasty PoC, worawit PoC, ExploitDB, GTFOBins, CWE mapping |
docs/mitigation.md | apt-get install --only-upgrade sudo, verification canary, AppArmor hardening, auditd monitoring, hardening table |
Member 4 — Proof Collection, Reporting & Integration
| File | Description |
|---|
proof/terminal_logs.txt | Evidence collection template (fill in with actual lab output) |
proof/screenshots/ | Directory for 7 required screenshots |
report/CVE-2021-3156_Report.docx | 12-section professional report: cover page, executive summary, CVE description, root cause analysis, CVSS breakdown, exploitation steps, code explanation, proof checklist, mitigation, timeline, references, disclaimer |
Quick Start
1. Build & Start the Lab
cd CVE-2021-3156-Project/lab/
# Build the vulnerable image (downloads Ubuntu 20.04, pins sudo 1.8.31)
docker compose build
# Start both containers
docker compose up -d
# Confirm containers are running
docker compose ps
Expected:
NAME STATUS
baron_samedit_target running
baron_samedit_patched running
2. Enter the Vulnerable Container
docker exec -it baron_samedit_target bash
3. Confirm Vulnerability Conditions
# Inside the container as labuser
whoami # Expected: labuser
id # Expected: uid=1000(labuser)...
sudo --version # Expected: Sudo version 1.8.31
sudo -l # Expected: Sorry, user labuser may not run sudo...
sudoedit -s '\' 2>&1 # Expected: NOT "usage:" → VULNERABLE
4. Copy and Run the Exploit