CVE-2016-7076: Command Injection
Last updated 25 August 2025
Other sources
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-7076.
What is the severity rating of CVE-2016-7076?
CVE-2016-7076 has a severity rating of 7.8 (high).
What is the affected software for CVE-2016-7076?
The affected software for CVE-2016-7076 includes sudo versions before 1.8.18p1.
How can this vulnerability be exploited?
This vulnerability can be exploited by a local user who is permitted to run an application via sudo with the noexec restriction.
Are there any known fixes for this vulnerability?
Yes, there are known fixes for this vulnerability. Please refer to the references for more information.