OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28339.json",
"cna_assigner": "mitre"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.8.2"
},
{
"last_affected": "6.8.2"
}
],
"cpe": "cpe:2.3:a:opendoas_project:opendoas:*:*:*:*:*:*:*:*",
"source": [
"DESCRIPTION",
"CPE_RANGE"
]
}[
{
"signature_type": "Function",
"digest": {
"function_hash": "226438582451453904082522244073761597401",
"length": 4421.0
},
"target": {
"file": "doas.c",
"function": "main"
},
"signature_version": "v1",
"id": "CVE-2023-28339-7115ead5",
"source": "https://github.com/duncaen/opendoas/commit/7f0205fe2f06221d76243342d299851f48c2b83c",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"134337381104205371149834042256174123933",
"240490000281492794839122102025649612068",
"178507194066844576015403433077282144014"
],
"threshold": 0.9
},
"target": {
"file": "doas.c"
},
"signature_version": "v1",
"id": "CVE-2023-28339-bdc6ab92",
"source": "https://github.com/duncaen/opendoas/commit/7f0205fe2f06221d76243342d299851f48c2b83c",
"deprecated": false
}
]
"2026-07-15T01:36:37Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-28339.json"