CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html

70 points · 13 comments · view on lemmy.world

13 Comments

CubitOom@infosec.pub · 25 pts · 309d

This vulnerability could allow a local attacker to leverage sudo's -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

original_reader@lemmy.zip · 24 pts · 309d (7 replies)

The vulnerability in question is CVE-2025-32463 (CVSS score: 9.3), which affects Sudo versions prior to 1.9.17p1

Check your version: sudo --version

As mentioned above, sudo version 1.9.17p1 patches this. This version was already released in June of this year, so many distributions should have it.

perishthethought@piefed.social · 9 pts · 309d (4 replies)

On Ubuntu 24.04

Sudo version 1.9.15p5

Eep!

sem@lemmy.blahaj.zone · 4 pts · 309d (1 reply)

Wait, shouldn't Ubuntu 24.04 LTS get security bugfixes?

SSUPII@sopuli.xyz · 3 pts · 308d

It does. In fact it is fixed.

All decent LTS/stable distros will cherrypick security fixes into whatever version they stabilized themselves on.

GJdan@programming.dev · 3 pts · 309d

It should be backported in supported ubuntu versions.

sudo apt changelog sudo

::: spoiler Tap for spoiler

sudo (1.9.15p5-3ubuntu5.24.04.1) noble-security; urgency=medium

  • SECURITY UPDATE: Local Privilege Escalation via host option
    • debian/patches/CVE-2025-32462.patch: only allow specifying a host when listing privileges.
    • CVE-2025-32462
  • SECURITY UPDATE: Local Privilege Escalation via chroot option
    • debian/patches/CVE-2025-32463.patch: remove user-selected root directory chroot option.
    • CVE-2025-32463

-- Marc Deslauriers marc.deslauriers@ubuntu.com Wed, 25 Jun 2025 08:42:53 -0400

:::

fmstrat@lemmy.nowsci.com · 3 pts · 309d

p5. The patch was backported.

HubertManne@piefed.social · 4 pts · 309d

Its funny because whenever I hear about something like this with foss it tends to be this way but when its proprietary I hear on how they were informed a while back, never patched it, and the founder of the bug is now disclosing based on the timetable they gave the. Feels that way anyway.

Cyber@feddit.uk · 2 pts · 309d

Thanks for posting the version.

Looks like Arch updated to this version on 1st July.

My DMZ node had it installed a week later, so I'm all smug today

z3rOR0ne@lemmy.ml · 6 pts · 309d (2 replies)

Laughs in opendoas

caseyweederman@lemmy.ca · 4 pts · 309d

Ah yes. Security through obscurity.

eleijeep@piefed.social · 4 pts · 309d

nice meme

9488fcea02a9@sh.itjust.works · 1 pts · 308d

I tried using the systemd alternatie, run0 or whatever.... it's really weird