PT-2026-83453 · Sudo · Sudo
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
sudo versions prior to 1.9.17p3
Description
In ptrace-based intercept mode, the software fails to apply intercept policy checks to the
execveat system call. This allows users who are permitted to run specific commands to execute denied programs by calling execveat directly or through fexecve, which bypasses policy enforcement and logging.Recommendations
Update to version 1.9.17p3 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sudo