UbuntuUpdates.org

Package "sudo"

Name: sudo

Description:

Provide limited super user privileges to specific users

Latest version: 1.9.15p5-3ubuntu5.24.04.2
Release: noble (24.04)
Level: updates
Repository: main
Homepage: https://www.sudo.ws/

Links


Download "sudo"


Other versions of "sudo" in Noble

Repository Area Version
base universe 1.9.15p5-3ubuntu5
base main 1.9.15p5-3ubuntu5
security main 1.9.15p5-3ubuntu5.24.04.2
security universe 1.9.15p5-3ubuntu5.24.04.2
updates universe 1.9.15p5-3ubuntu5.24.04.2

Changelog

Version: 1.9.15p5-3ubuntu5.24.04.2 2026-03-13 12:08:04 UTC

  sudo (1.9.15p5-3ubuntu5.24.04.2) noble-security; urgency=medium

  * SECURITY UPDATE: exec_mailer gid issue (LP: #2143042)
    - debian/patches/lp2143042.patch: set group as well as uid when running
      the mailer and make a setuid(), setgid() or setgroups() failure fatal
      in include/sudo_eventlog.h, lib/eventlog/eventlog.c,
      lib/eventlog/eventlog_conf.c, plugins/sudoers/logging.c,
      plugins/sudoers/policy.c.
    - No CVE number

 -- Marc Deslauriers <email address hidden> Mon, 02 Mar 2026 07:56:19 -0500

Source diff to previous version
2143042 exec_mailer: Set group as well as uid when running the mailer

Version: 1.9.15p5-3ubuntu5.24.04.1 2025-06-30 21:14:05 UTC

  sudo (1.9.15p5-3ubuntu5.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: Local Privilege Escalation via host option
    - debian/patches/CVE-2025-32462.patch: only allow specifying a host
      when listing privileges.
    - CVE-2025-32462
  * SECURITY UPDATE: Local Privilege Escalation via chroot option
    - debian/patches/CVE-2025-32463.patch: remove user-selected root
      directory chroot option.
    - CVE-2025-32463

 -- Marc Deslauriers <email address hidden> Wed, 25 Jun 2025 08:42:53 -0400

CVE-2025-32462 Local Privilege Escalation via host option
CVE-2025-32463 Local Privilege Escalation via chroot option



About   -   Send Feedback to @ubuntu_updates