Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35535

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 7.4

Описание

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

A flaw was found in Sudo. A local user could exploit a failure in the setuid, setgid, or setgroups calls, which are used to drop privileges before running the mailer. This oversight allows for privilege escalation, enabling the user to gain elevated access on the system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-272
https://bugzilla.redhat.com/show_bug.cgi?id=2454714sudo: Sudo: Privilege escalation due to failure in privilege drop calls

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
nvd
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
msrc
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
debian
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...

suse-cvrf
3 месяца назад

Security update for sudo

7.4 High

CVSS3