A heap overflow vulnerability has been hiding in plain sight for nearly 10 years. Any unprivileged user can gain root privileges on a vulnerable host using a default sudo configuration by exploiting this vulnerability. The vulnerability affects all legacy versions from 1.8.2 to 1.9.5p1 in their default configuration. Other operating systems and distributions are also likely to be exploitable. It has been reported that macOS, AIX, and.Solaris are also vulnerable to CVE-2021-3156.”]

