CVE-2025-32463
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 55% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-829
מוצרים מושפעים
sudo_project: sudo; canonical: ubuntu linux; debian: debian linux; opensuse: leap; redhat: enterprise linux; suse: linux enterprise desktop; suse: linux enterprise real time; suse: linux enterprise server for sap
קישורים
- https://www.sudo.ws/security/advisories/ Vendor Advisory
- https://www.sudo.ws/security/advisories/chroot_bug/ Vendor Advisory
- https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to… ExploitThird Party Advisory
- https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot ExploitThird Party Advisory
- https://access.redhat.com/security/cve/cve-2025-32463 Third Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463 Issue TrackingThird Party Advisory
- https://explore.alas.aws.amazon.com/CVE-2025-32463.html Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-32463 Third Party Advisory
- https://ubuntu.com/security/notices/USN-7604-1 Third Party Advisory
- https://www.openwall.com/lists/oss-security/2025/06/30/3 Third Party Advisory