Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19220

Опубликовано: 12 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-19220: sudo security update (IMPORTANT)

[1.9.17p2-3]

  • CVE-2026-35535 sudo: Privilege escalation due to failure in privilege drop calls Resolves: RHEL-166069

[1.9.17p2-2]

  • Request to backport support for regex in sudo [rhel-9] Resolves: RHEL-1376
  • Rebase of sudo to 1.9.17p2 [rhel-9] Resolves: RHEL-128623
  • sudo passes SHELL environment variable twice to the shell being executed [rhel-9] Resolves: RHEL-127359

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

sudo

1.9.17p2-3.el9_8

sudo-python-plugin

1.9.17p2-3.el9_8

Oracle Linux x86_64

sudo

1.9.17p2-3.el9_8

sudo-python-plugin

1.9.17p2-3.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
redhat
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
nvd
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...