Protection mechanism failure in Sudo - CVE-2025-32463

 

Protection mechanism failure in Sudo - CVE-2025-32463

Published: July 1, 2025 / Updated: September 24, 2025


Vulnerability identifier: #VU112066
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32463
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient implementation of security measures when running sudo with -R (--chroot) option. A local user can run arbitrary commands as root, even if they are not listed in the sudoers file.

Note, the vulnerability affects installations with Name Service Switch (NSS) enabled. 


Affected software

Sudo
Gentoo Linux
Ubuntu
Anolis OS
openEuler
LANTIME Operating System Firmware (LTOS)
app-admin/sudo
sudo (Ubuntu package)
sudo-python-plugin
sudo-logsrvd
sudo-devel
sudo
sudo-debugsource
sudo-help
sudo-debuginfo
sudo (Red Hat package)

How to mitigate CVE-2025-32463

Install updates from vendor's website.

Sudo - update to 1.9.17p1
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
app-admin/sudo - update to 1.8.5
sudo (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.5, 1.9.15p5-3ubuntu5.24.04.1, 1.9.15p5-3ubuntu5.24.10.1, 1.9.16p2-1ubuntu1.1
sudo-python-plugin - update to 1.9.15p5-3
sudo-logsrvd - update to 1.9.15p5-3
sudo-devel - update to 1.9.15p5-3
sudo - update to 1.9.15p5-3
sudo-debugsource - update to 1.9.15p5-4
sudo-help - update to 1.9.15p5-4
sudo-devel - update to 1.9.15p5-4
sudo-debuginfo - update to 1.9.15p5-4
sudo - update to 1.9.15p5-4
sudo (Red Hat package) - update to 1.9.15-8.p5.el10_0.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins