Описание
ELSA-2026-11521: sudo security update (IMPORTANT)
[1.9.5p2-1.0.1.el8_10.5]
- Fixes sudo -s unclosed sessions when use_pty option used [Orabug: 36952911]
[1.9.5p2-1.5] RHEL 8.10.0.Z ERRATUM
- CVE-2026-35535 - Privilege escalation due to failure in privilege drop calls Resolves: RHEL-166060
[1.9.5p2-1.3] RHEL 8.10.0.Z ERRATUM
- sudo passes SHELL environment variable twice to the shell being executed [rhel-8] Resolves: RHEL-127360
[1.9.5p2-1.2] RHEL 8.10.0.Z ERRATUM
- Reintroduce cmnd_no_wait Resolves: RHEL-51956
- Missing separator in the log Resolves: RHEL-71913
[1.9.5p2-1.1] RHEL 8.10.0.Z ERRATUM
- CVE-2025-32462 sudo: LPE via host option Resolves: RHEL-100014
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
sudo
1.9.5p2-1.0.1.el8_10.5
Oracle Linux x86_64
sudo
1.9.5p2-1.0.1.el8_10.5
Связанные CVE
Связанные уязвимости
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...