CVE-2023-28339
Publication date 14 March 2023
Last updated 11 February 2026
Ubuntu priority
Cvss 3 Severity Score
Description
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| doas | ||
| 22.04 LTS jammy |
Vulnerable, fix deferred
|
|
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| opendoas | 26.04 LTS resolute |
Vulnerable, fix deferred
|
| 24.04 LTS noble |
Vulnerable, fix deferred
|
|
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release |
Notes
john-breton
Upstream argues this is a problem with the kernel and not in OpenDoas. As of Linux 6.7, both TIOCSTI and TIOCLINUX can be disabled to prevent this issue. No patch currently exists as of 2026-02-11, and the issue discussing the vulnerability has not received any updates since early 2024.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
8.8 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H