CVE-2023-42465

HIGH

sudo < 1.9.15 - Authentication Bypass and Privilege Escalation via Row Hammer Bit Flip

Title source: llm
STIX 2.1

Description

Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.

Scores

CVSS v3 7.0
EPSS 0.0054
EPSS Percentile 41.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
sudo_project/sudo < 1.9.15
Published Dec 22, 2023
Tracked Since Feb 18, 2026