CVE-2023-27320

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
28/02/2023
Last modified:
21/03/2025

Description

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* 1.9.8 (including) 1.9.13 (excluding)
cpe:2.3:a:sudo_project:sudo:1.9.13:-:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.13:p1:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*