Описание
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| sudo | fixed | 1.9.17p2-5 | package | |
| sudo | fixed | 1.9.16p2-3+deb13u2 | trixie | package |
| sudo | fixed | 1.9.13p3-1+deb12u4 | bookworm | package |
Примечания
Introduced by: https://github.com/sudo-project/sudo/commit/bd1ca79cca827a92e904f022e49df121931d4ff5 (SUDO_1_9_4p1)
Fixed by: https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69
https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042
EPSS
Связанные уязвимости
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
EPSS