PT-2026-90015 · Canonical · Rust-Sudo-Rs
Published
2026-09-01
·
Updated
2026-09-01
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was discovered that sudo-rs incorrectly handled time-of-check vs time-
of-use conditions in sudoedit. A local attacker with permission to edit
specific files using sudoedit could use this issue to place files in
arbitrary directories, and possibly escalate their privileges. This issue
only affected systems configured to grant fine-grained sudoedit file
editing permissions, which is not the default configuration.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rust-Sudo-Rs