Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
https://www.sudo.ws/releases/stable/#1.9.13p2
https://www.openwall.com/lists/oss-security/2023/02/28/1
https://security.netapp.com/advisory/ntap-20230413-0009/
https://security.gentoo.org/glsa/202309-12
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/
http://www.openwall.com/lists/oss-security/2023/03/01/8
Source: Mitre, NVD
Published: 2023-02-28
Updated: 2023-11-07
Base Score: 8.3
Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C
Severity: High
Base Score: 7.2
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H