Описание
Security update for sudo
This update for sudo fixes the following issues:
- CVE-2026-35535: unhandled failure of
setuid,setgidorsetgroupscalls during a mailer privilege drop allows for local privilege escalation (bsc#1261420).
Список пакетов
openSUSE Leap 16.0
sudo-1.9.17p1-160000.3.1
sudo-devel-1.9.17p1-160000.3.1
sudo-plugin-python-1.9.17p1-160000.3.1
sudo-policy-sudo-auth-self-1.9.17p1-160000.3.1
sudo-policy-wheel-auth-self-1.9.17p1-160000.3.1
sudo-test-1.9.17p1-160000.3.1
system-group-sudo-1.9.17p1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1261420
- SUSE CVE CVE-2026-35535 page
Описание
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Затронутые продукты
openSUSE Leap 16.0:sudo-1.9.17p1-160000.3.1
openSUSE Leap 16.0:sudo-devel-1.9.17p1-160000.3.1
openSUSE Leap 16.0:sudo-plugin-python-1.9.17p1-160000.3.1
openSUSE Leap 16.0:sudo-policy-sudo-auth-self-1.9.17p1-160000.3.1
Ссылки
- CVE-2026-35535
- SUSE Bug 1261420