Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via “sudoedit -s” and a command-line argument that ends with a single backslash character.
The bug, CVE identifier of CVE-2021-3156, known as “Baron Samedit“ was found by Qualys Team and was patched earlier this week with the release of Sudo v1.9.5p2.
Qualys Video: