PT-2025-27465 · Sudo +7 · Sudo +7

Rich Mirch

·

Published

2025-06-30

·

Updated

2025-07-17

·

CVE-2025-32462

CVSS v3.1
2.8
VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

## Vulnerability Report

**Name of the Vulnerable Software and Affected Versions:**

Sudo versions prior to 1.9.17p1

Sudo versions 1.8.8 through 1.9.17

Sudo versions prior to 1.9.5p2-3+deb11u2 (Debian 11 bullseye)

Sudo versions prior to 1.9.13p3-1+deb12u2 (Debian bookworm)

Sudo versions prior to 1.9.16p2-1ubuntu1.1 (Ubuntu plucky)

Sudo versions prior to 1.8.31-1ubuntu1.5+esm1 (Ubuntu 20.04 LTS, 18.04 LTS, 16.04 LTS, and 14.04 LTS)

**Description:**

Sudo, a program designed to provide limited super user privileges, contains a vulnerability related to the handling of the `-h` or `--host` option. The `-h` option was not correctly restricted to listing privileges and could be misused when running commands via `sudo` or editing files with `sudoedit`. This flaw could allow a local attacker to escalate their privileges. The vulnerability stems from a logic bypass in the host matching functionality, potentially allowing a user to execute commands with elevated privileges on unintended machines.

**Recommendations:**

- Upgrade to Sudo version 1.9.17p1 or later.

- For Debian 11 bullseye, upgrade to Sudo version 1.9.5p2-3+deb11u2 or later.

- For Debian bookworm, upgrade to Sudo version 1.9.13p3-1+deb12u2 or later.

- For Ubuntu plucky, upgrade to Sudo version 1.9.16p2-1ubuntu1.1 or later.

- For Ubuntu 20.04 LTS, 18.04 LTS, 16.04 LTS, and 14.04 LTS, upgrade to version 1.8.31-1ubuntu1.5+esm1 or later.

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALSA-2025:10110
ALSA-2025:9978
ALT-PU-2025-8851
ALT-PU-2025-8863
BDU:2025-08356
CESA-2025_10110
CVE-2025-32462
DLA-4235-1
DSA-5954-1
RHSA-2025:10110
RHSA-2025:9978
RHSA-2025_10110
RHSA-2025_9978
SUSE-SU-2025:02174-1
SUSE-SU-2025:02175-1
SUSE-SU-2025:02177-1
SUSE-SU-2025:02178-1
SUSE-SU-2025:02179-1
USN-7604-1
USN-7604-2

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Red Os
Sudo
Ubuntu