Bug 1208595 (CVE-2023-27320) - VUL-0: CVE-2023-27320: sudo: double free with per-command chroot sudoers rules
Summary: VUL-0: CVE-2023-27320: sudo: double free with per-command chroot sudoers rules
Status: RESOLVED FIXED
: 1208596 (view as bug list)
Alias: CVE-2023-27320
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/358068/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-27320:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-02-23 08:43 UTC by Robert Frohl
Modified: 2024-05-06 08:18 UTC (History)
6 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Thomas Leroy 2023-02-23 08:47:06 UTC
*** Bug 1208596 has been marked as a duplicate of this bug. ***
Comment 5 Jason Sikes 2023-02-28 01:28:59 UTC
Issue has appeared in the changelog of sudo upstream.

In SLE:

| SUSE:SLE-15-SP4:Update | created request id 290896 |
| SUSE:SLE-15-SP5:GA     | created request id 290898 |
Comment 6 Jason Sikes 2023-02-28 01:45:02 UTC
Updated Factory to 1.9.13p2 which addresses this issue.

created request id 1068080

Handing off to security-team.
Comment 8 Alexander Bergmann 2023-02-28 07:29:54 UTC
Public!
Comment 9 Alexander Bergmann 2023-03-01 08:52:14 UTC
CVE-2023-27320 was assigned to this issue.
Comment 10 Robert Frohl 2023-03-01 08:54:00 UTC
Fixed a potential double-free bug when matching a sudoers rule that contains a per-command chroot directive (CHROOT=dir). This bug was introduced in sudo 1.9.8

https://www.sudo.ws/releases/stable/#1.9.13p2
Comment 13 OBSbugzilla Bot 2023-03-17 10:45:02 UTC
This is an autogenerated message for OBS integration:
This bug (1208595) was mentioned in
https://build.opensuse.org/request/show/1072565 Factory / sudo
Comment 17 Otto Hollmann 2023-03-23 13:18:49 UTC
Resubmitted with modified *changes file: 

SUSE:SLE-15-SP4:Update 292876
SUSE:SLE-15-SP5:GA     292874

Assigning back to security team.
Comment 19 Maintenance Automation 2023-03-29 12:30:14 UTC
SUSE-SU-2023:1665-1: An update that solves three vulnerabilities and has three fixes can now be installed.

Category: security (moderate)
Bug References: 1203201, 1206483, 1206772, 1208595, 1209361, 1209362
CVE References: CVE-2023-27320, CVE-2023-28486, CVE-2023-28487
Sources used:
openSUSE Leap Micro 5.3 (src): sudo-1.9.9-150400.4.26.1
openSUSE Leap 15.4 (src): sudo-1.9.9-150400.4.26.1
SUSE Linux Enterprise Micro for Rancher 5.3 (src): sudo-1.9.9-150400.4.26.1
SUSE Linux Enterprise Micro 5.3 (src): sudo-1.9.9-150400.4.26.1
SUSE Linux Enterprise Micro for Rancher 5.4 (src): sudo-1.9.9-150400.4.26.1
SUSE Linux Enterprise Micro 5.4 (src): sudo-1.9.9-150400.4.26.1
Basesystem Module 15-SP4 (src): sudo-1.9.9-150400.4.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Robert Frohl 2024-05-06 08:18:04 UTC
done, closing