CVE-2017-1000367 is a local vulnerability in sudo on Linux affecting get_process_ttyname() and related tty-resolution logic. Sudo reads /proc/[pid]/stat and parses the controlling tty device number from field 7, but its parsing was unsafe because field 2 (comm, the executable name) can contain embedded spaces. By invoking sudo through a crafted symlink whose filename contains whitespace and a chosen number, an attacker can cause sudo to misparse /proc/[pid]/stat and use an attacker-controlled tty device number. If sudo does not find the device under /dev/pts, it performs a breadth-first traversal of /dev; Qualys showed this can be abused, including via world-writable locations such as /dev/shm and race conditions, to make sudo treat an arbitrary character device, and after additional races, an arbitrary file, as the user's tty. On SELinux-enabled systems with sudo built with SELinux support, relabel_tty() opens this resolved tty path with O_RDWR|O_NONBLOCK and dup2()s it onto the command's stdin, stdout, and stderr. This enables terminal hijacking or arbitrary file overwrite, and can be leveraged by a user with sudo rights to obtain full root privileges. The issue affected sudo 1.8.20 and earlier; the supplied content also states affected ranges of 1.7.10 through 1.7.10p9 and 1.8.5 through 1.8.20p1, with 1.8.20p1 containing only an incomplete fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single C source file, 'sudopwn.c', which implements a local privilege escalation exploit targeting the 'sudo' binary on Linux systems. The exploit works by creating a temporary directory in /dev/shm, setting up symlinks to /usr/bin/sudo and a pseudo-terminal device, and monitoring file events using inotify. It manipulates process priorities and scheduling, and attempts to execute sudo with crafted arguments, possibly exploiting a race condition or symlink vulnerability. The code is a proof-of-concept and requires local access to the target system. The main endpoints involved are file paths in /dev/shm, /usr/bin/sudo, /dev/pts/57, and /etc/PWN. The exploit does not target a specific CVE but is clearly designed to manipulate sudo's behavior for privilege escalation.
This repository contains a proof-of-concept exploit for CVE-2017-1000367, a vulnerability in sudo's SELinux support on Linux systems. The exploit is implemented in C (sudopwn.c) and is accompanied by a README.md with compilation and usage instructions. The exploit works by creating a temporary directory in /dev/shm/_tmp, setting up symlinks to /dev/pts/57, /usr/bin/sudo, and later /etc/motd, and then executing sudo with a specific SELinux role override to run /usr/bin/sum. The exploit leverages inotify to monitor file events and attempts to exploit a race condition in sudo's handling of SELinux roles. The attack is local and requires the user to have sudo permissions for a specific command. The repository is a single-file proof-of-concept and does not include weaponized or framework-based code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.