PT-2026-29973 · Sudo+1 · Sudo+1

Marc Deslauriers

+1

·

Published

2026-03-12

·

Updated

2026-05-19

·

CVE-2026-35535

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sudo versions through 1.9.17p2
Description A failure of a setuid, setgid, or setgroups call during a privilege drop before running the mailer is not a fatal error and can lead to privilege escalation.
Recommendations Update Sudo to a version later than 1.9.17p2.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALSA-2026:10758
ALSA-2026:11521
ALSA-2026:12310
ALSA-2026:19067
ALSA-2026:19220
BDU:2026-04709
CVE-2026-35535
ECHO-34C9-A519-4B5C
OESA-2026-1908
OESA-2026-1996
OESA-2026-1997
OESA-2026-1998
OESA-2026-1999
OPENSUSE-SU-2026:10510-1
OPENSUSE-SU-2026:20604-1
RHSA-2026:10758
RHSA-2026:11521
RHSA-2026:12310
RHSA-2026:13731
RHSA-2026:13888
RHSA-2026:13889
RHSA-2026:13891
RHSA-2026:13892
RHSA-2026:13895
RHSA-2026:13896
RHSA-2026:14228
RHSA-2026:14437
RHSA-2026:19067
RHSA-2026:19220
SUSE-SU-2026:1308-1
SUSE-SU-2026:1309-1
SUSE-SU-2026:1359-1
SUSE-SU-2026:21252-1
SUSE-SU-2026:21273-1
USN-8092-1

Affected Products

Rocky Linux
Sudo