macOS Big Sur 11.2.1 Fixes Root Access Sudo Bug

The macOS Big Sur 11.2.1 update that Apple released today fixes a sudo security vulnerability that could allow an attacker to gain root access to a Mac.

sudo bug macos
According to an Apple security support document, the bug, CVE-2021-3156, was addressed in the update by updating to sudo version 1.9.5p2. Apple has also fixed the bug in Supplemental Updates made available for macOS Catalina 10.15.7 and macOS Mojave 10.14.6.

The updates also include fixes for two bugs that could allow an app to execute arbitrary code with kernel privileges.

Discovered last week, the vulnerability triggers a "heap overflow" in sudo that changes the current user's privileges to enable root-level access, giving an attacker access to the entire system.

Top Rated Comments

neuropsychguy Avatar
8 months ago

Is Apple the first? Did other Unix and Linux push out the update too?
Most major Linux distros have already fixed it.

Examples:
https://ubuntu.com/security/CVE-2021-3156
https://access.redhat.com/security/cve/cve-2021-3156
https://www.suse.com/security/cve/CVE-2021-3156/
https://bodhi.fedoraproject.org/updates/FEDORA-2021-2cb63d912a
Score: 6 Votes (Like | Disagree)
luvbug Avatar
8 months ago
Thank you! Much more than a charging bug, for sure.
Score: 6 Votes (Like | Disagree)
TriBruin Avatar
8 months ago

Now if it could just come standard with allowing us to use TouchID instead of typing our password.
You know that you can enable this feature. Unfortunately, it has to be re-enabled after each update.

https://derflounder.wordpress.com/2017/11/17/enabling-touch-id-authorization-for-sudo-on-macos-high-sierra/
Score: 5 Votes (Like | Disagree)
ruka.snow Avatar
8 months ago
Fantastic. Unlikely to affect me but still good to have the furniture nailed down.
Score: 4 Votes (Like | Disagree)
Jerry Fritschle Avatar
8 months ago

Reminds me of High Sierra. Waiting for the login “root” user access now. :p
I admit I thought of that, too. However, "sudo" is a utility found throughout unix/Linux systems. This was therefore not an "Apple" bug, but rather an update that had to come from upstream :-)
Score: 3 Votes (Like | Disagree)
Rafterman Avatar
8 months ago
Thanks Apple for yet another reboot. Get it right the first time.
Score: 2 Votes (Like | Disagree)

Top Stories

macOS Big Sur Feature Purple

Apple Seeds First Beta of macOS Big Sur 11.4 to Developers [Update: Public Beta Available]

Wednesday April 21, 2021 10:26 am PDT by
Apple today seeded the first beta of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming while the macOS 11.3 beta is still in testing. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple Developer Center. According...
sudo bug macos

Root Access Sudo Bug Found to Affect macOS Big Sur

Wednesday February 3, 2021 9:20 am PST by
A sudo bug that can grant an attacker root access has been discovered to affect macOS Big Sur (via ZDNet). The security vulnerability, identified last week as "CVE-2021-3156" by the Qualys Security Team, affects sudo, which is a program that allows users to run commands with the security privileges of another user, such as an administrator. The bug triggers a "heap overflow" in sudo that...
macOS 11

Apple Seeds Release Candidate Version of macOS Big Sur 11.2 to Developers and Public Beta Testers

Thursday January 21, 2021 1:40 pm PST by
Apple today seeded the RC version of an upcoming macOS Big Sur 11.2 update to developers for testing purposes, with the new beta coming a week after the second beta and two months after initial macOS Big Sur release. Developers can download the ‌‌macOS Big Sur‌‌ 11.2 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple...
safari macos icon banner

Apple Releases New Safari 14.1 Update for macOS Catalina and Mojave With Security Fix

Tuesday May 4, 2021 2:32 pm PDT by
Apple today released a new version of Safari 14.1 for macOS Catalina and macOS Mojave users, with the update introducing fixes for two WebKit vulnerabilities that were patched in macOS Big Sur yesterday. Apple's support document for the updated Safari release confirms that it addresses the same WebKit memory corruption issue and an integer overflow bug for users of older versions of macOS. ...
First Look Big Sur Feature2

Apple Releases macOS Big Sur 11.2.1 With Fix for MacBook Pro Charging Issue [Updated]

Tuesday February 9, 2021 10:13 am PST by
Apple today released macOS Big Sur 11.2.1, the third update to the macOS Big Sur operating system that launched in November. macOS Big Sur‌ 11.2.1 comes a little over a week after the release of macOS 11.2. The new ‌‌‌macOS Big Sur‌‌ 11.2.1‌ update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences. According to Apple's...
macOS Big Sur Feature Blue

Apple Seeds Seventh Beta of macOS Big Sur 11.3 to Developers

Thursday April 8, 2021 10:07 am PDT by
Apple today seeded the seventh beta of an upcoming macOS Big Sur 11.3 update to developers for testing purposes, with the new beta coming one week after the launch of the sixth beta and more than a month after the release of macOS Big Sur 11.2, a bug fix update. Developers can download the ‌‌macOS Big Sur‌‌ 11.3 beta using the Software Update mechanism in System Preferences after...
macOS Big Sur Feature Orange

Apple Releases macOS Big Sur 11.4 With Apple Podcasts Subscription Support

Monday May 24, 2021 10:08 am PDT by
Apple today released macOS Big Sur 11.4, the fourth major update to the macOS Big Sur operating system that launched in November 2020. macOS Big Sur comes one month after the release of macOS Big Sur 11.3, an update that added M1 optimizations, AirTag integration, and more. The new ‌‌‌‌macOS Big Sur‌‌‌ 11.4 update can be downloaded for free on all eligible Macs using the...
macOS Big Sur Feature Purple

Apple Seeds RC Version of macOS Big Sur 11.3 to Developers

Tuesday April 20, 2021 11:16 am PDT by
Apple today seeded the RC version of an upcoming macOS Big Sur 11.3 update to developers for testing purposes, with the new beta coming one week after the launch of the eighth beta and more than two months after the release of macOS Big Sur 11.2, a bug fix update. Developers can download the ‌‌macOS Big Sur‌‌ 11.3 beta using the Software Update mechanism in System Preferences after...
macOS 11

Apple Seeds Third Release Candidate Version of macOS Big Sur 11.2 to Developers [Update: Public Beta Too]

Thursday January 28, 2021 1:29 pm PST by
Apple today seeded a third RC version of an upcoming macOS Big Sur 11.2 update to developers for testing purposes, with the new update coming a week after the second RC and more than two months after initial macOS Big Sur release. Developers can download the updated ‌‌macOS Big Sur‌‌ 11.2 release candidate using the Software Update mechanism in System Preferences after installing the ...
iOS 14 on iPhone feature emergency

Apple Seeds First Public Betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5

Thursday May 20, 2021 10:11 am PDT by
Apple today seeded the first public betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5 to public beta testers, one day after seeding first betas to developers. Public beta testers who have signed up for the beta testing program can download the iOS and iPadOS‌ 14.7 updates over the air after installing the proper certificate from the Public Beta website on an iOS device. macOS Big Sur...