Описание
ELSA-2026-19220: sudo security update (IMPORTANT)
[1.9.17p2-3]
- CVE-2026-35535 sudo: Privilege escalation due to failure in privilege drop calls Resolves: RHEL-166069
[1.9.17p2-2]
- Request to backport support for regex in sudo [rhel-9] Resolves: RHEL-1376
- Rebase of sudo to 1.9.17p2 [rhel-9] Resolves: RHEL-128623
- sudo passes SHELL environment variable twice to the shell being executed [rhel-9] Resolves: RHEL-127359
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
sudo
1.9.17p2-3.el9_8
sudo-python-plugin
1.9.17p2-3.el9_8
Oracle Linux x86_64
sudo
1.9.17p2-3.el9_8
sudo-python-plugin
1.9.17p2-3.el9_8
Связанные CVE
Связанные уязвимости
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...