Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35535

Опубликовано: 03 апр. 2026
Источник: debian
EPSS Низкий

Описание

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sudofixed1.9.17p2-5package
sudofixed1.9.16p2-3+deb13u2trixiepackage
sudofixed1.9.13p3-1+deb12u4bookwormpackage

Примечания

  • Introduced by: https://github.com/sudo-project/sudo/commit/bd1ca79cca827a92e904f022e49df121931d4ff5 (SUDO_1_9_4p1)

  • Fixed by: https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69

  • https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt

  • https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042

EPSS

Процентиль: 7%
0.00173
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
redhat
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
nvd
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
msrc
4 месяца назад

Описание отсутствует

suse-cvrf
3 месяца назад

Security update for sudo

EPSS

Процентиль: 7%
0.00173
Низкий