Protection mechanism failure in Sudo - CVE-2025-32463
Published: July 1, 2025 / Updated: September 24, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient implementation of security measures when running sudo with -R (--chroot) option. A local user can run arbitrary commands as root, even if they are not listed in the sudoers file.
Note, the vulnerability affects installations with Name Service Switch (NSS) enabled.
Affected software
Gentoo Linux
Ubuntu
Anolis OS
openEuler
LANTIME Operating System Firmware (LTOS)
app-admin/sudo
sudo (Ubuntu package)
sudo-python-plugin
sudo-logsrvd
sudo-devel
sudo
sudo-debugsource
sudo-help
sudo-debuginfo
sudo (Red Hat package)
How to mitigate CVE-2025-32463
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
app-admin/sudo - update to 1.8.5
sudo (Ubuntu package) - addressed in versions 1.9.9-1ubuntu2.5, 1.9.15p5-3ubuntu5.24.04.1, 1.9.15p5-3ubuntu5.24.10.1, 1.9.16p2-1ubuntu1.1
sudo-python-plugin - update to 1.9.15p5-3
sudo-logsrvd - update to 1.9.15p5-3
sudo-devel - update to 1.9.15p5-3
sudo - update to 1.9.15p5-3
sudo-debugsource - update to 1.9.15p5-4
sudo-help - update to 1.9.15p5-4
sudo-devel - update to 1.9.15p5-4
sudo-debuginfo - update to 1.9.15p5-4
sudo - update to 1.9.15p5-4
sudo (Red Hat package) - update to 1.9.15-8.p5.el10_0.2
Links to Public Exploits and PoC-codes
- Exploit #11981 - CVE-2025-32463_chwoot (? Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.) (September 24, 2025)
- Exploit #11921 - Sudo Chroot 1.9.17 Privilege Escalation (September 4, 2025)
- Exploit #11848 - CVE-2025-32463-POC (?️ Proof of Concept (PoC) for CVE-2025-32463 — Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational (August 8, 2025)
- Exploit #11809 - CVE-2025-32463_Sudo_PoC (August 1, 2025)
- Exploit #11803 - CVE-2025-32463 (July 21, 2025)
- Exploit #11784 - CVE-2025-32463 (July 18, 2025)
- Exploit #11781 - CVE-2025-32463_chwoot (Demonstrate CVE-2025-32463 with this PoC for sudo's chroot feature. Explore the exploit and its impact on vulnerable sudo versions. ???) (July 18, 2025)
- Exploit #11780 - CVE-2025-32463 (Local privilege escalation vulnerability CVE-2025-32463 in Sudo allows users to gain root access. Discover details and solutions on GitHub! ?✨) (July 18, 2025)
- Exploit #11752 - CVE-2025-32463 (July 3, 2025)
- Exploit #11748 - sudoinjection (July 3, 2025)
- Exploit #11747 - CVE-2025-32463-POC (July 3, 2025)
- Exploit #11742 - CVE-2025-32463_POC (July 3, 2025)
- Exploit #11739 - CVE-2025-32463_POC (July 3, 2025)
- Exploit #11737 - CVE-2025-32463 (July 3, 2025)
- Exploit #11736 - CVE-2025-32463_Exploit () (July 3, 2025)
External References
Related Security Bulletins
- Multiple vulnerabilities in Sudo
- Gentoo update for sudo
- Ubuntu update for sudo
- openEuler 24.03 LTS SP1 update for sudo
- openEuler 24.03 LTS update for sudo
- openEuler 24.03 LTS SP2 update for sudo
- Anolis OS update for sudo
- Red Hat Enterprise Linux 10 update for sudo
- Multiple vulnerabilities in Meinberg LANTIME firmware