PT-2025-27466 · Sudo+5 · Sudo+5
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sudo versions prior to 1.9.17p1
Description
Local users can obtain root access and execute arbitrary commands by exploiting a flaw in the Sudo utility. The issue occurs when the
--chroot (or -R) option is used, allowing the application to use a user-controlled /etc/nsswitch.conf file located within the chroot directory. This inclusion of functionality from an untrusted control sphere enables privilege escalation even if the user is not listed in the sudoers configuration file. This flaw has been identified as being actively exploited in the wild.Recommendations
Update Sudo to version 1.9.17p1 or later.
As a temporary containment measure, remove the SUID bit from
/usr/bin/sudo to prevent privilege elevation.Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Sudo
Suse
Ubuntu