Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19067

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-19067: sudo security update (IMPORTANT)

[1.9.17-4.p2]

  • Bump release number
  • Resolves: RHEL-164620 - CVE-2026-35535 sudo: Sudo: Privilege escalation due to failure in privilege drop calls

[1.9.17-3.p2]

  • Resolves: RHEL-164620 - CVE-2026-35535 sudo: Sudo: Privilege escalation due to failure in privilege drop calls

[1.9.17-2.p2]

  • Resolves: RHEL-59136 - sudo passes SHELL environment variable twice to the shell being executed [rhel-10]
  • Resolves: RHEL-128212 - [RFE] request to backport support for regex in sudo [rhel-10]
  • Resolves: RHEL-112100 - Rebase of sudo to 1.9.17p2 [rhel-10]

[1.9.17-1.p2]

  • Rebase sudo to 1.9.17p2
  • Resolves: RHEL-122752

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

sudo-python-plugin

1.9.17-4.p2.el10_2

sudo

1.9.17-4.p2.el10_2

Oracle Linux x86_64

sudo

1.9.17-4.p2.el10_2

sudo-python-plugin

1.9.17-4.p2.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
redhat
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
nvd
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...