Protection mechanism failure in Sudo - CVE-2025-32462

 

Protection mechanism failure in Sudo - CVE-2025-32462

Published: July 1, 2025 / Updated: February 27, 2026


Vulnerability identifier: #VU112067
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32462
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient implementation of security measures when running sudo with -h (--host) option. If the current configuration provides access to users based on the host they are allowed to execute commands, a local user can bypass such a restriction by providing the hostname via the "-h" option they are allowed to execute commands. The vulnerability affects systems that use a common sudoers file that is distributed to multiple machines or when LDAP-based sudoers (including SSSD) is used. 


Affected software

Sudo
Red Hat OpenShift Container Platform
Debian Linux
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
macOS
Fedora
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Financial Transaction Manager for RedHat OpenShift
Business Automation Insights
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
app-admin/sudo
sudo (Ubuntu package)
sudo-devel
sudo
sudo (Red Hat package)
sudo-debuginfo
sudo-debugsource
sudo-help
sudo (Debian package)
sudo-python-plugin
sudo-logsrvd
Red Hat Ceph Storage

How to mitigate CVE-2025-32462

Install updates from vendor's website.

Sudo - update to 1.9.17p1
Netcool Operations Insight - update to 1.6.15
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
macOS - update to 26.1 25B78
app-admin/sudo - update to 1.8.5
sudo (Ubuntu package) - addressed in versions 1.8.9p5-1ubuntu1.5+esm8, 1.8.16-0ubuntu1.10+esm3, 1.8.21p2-3ubuntu1.6+esm1, 1.8.31-1ubuntu1.5+esm1, 1.9.9-1ubuntu2.5, 1.9.15p5-3ubuntu5.24.04.1, 1.9.15p5-3ubuntu5.24.10.1, 1.9.16p2-1ubuntu1.1
sudo-devel - addressed in versions 1.8.23-10, 1.9.15p5-3
sudo - addressed in versions 1.8.23-10, 1.9.5p2-1.0.1, 1.9.15p5-3
sudo (Red Hat package) - addressed in versions 1.8.23-10.el7_9.4, 1.8.29-5.el8_2.3, 1.8.29-7.el8_4.3, 1.9.5p2-1.el8_6.1, 1.9.5p2-1.el8_8.1, 1.9.5p2-1.el8_10.1, 1.9.5p2-7.el9_0.5, 1.9.5p2-9.el9_2.3, 1.9.5p2-10.el9_4.1, 1.9.5p2-10.el9_6.1, 1.9.15-8.p5.el10_0.2
sudo - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-debuginfo - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-debugsource - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-devel - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-help - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo (Debian package) - update to 1.9.13p3-1+deb12u2
sudo-python-plugin - update to 1.9.15p5-3
sudo-logsrvd - update to 1.9.15p5-3
sudo - addressed in versions 1.9.17-2.p1.fc41, 1.9.17-2.p1.fc42
Red Hat OpenShift Container Platform - addressed in versions 4.12.79, 4.13.60, 4.14.55, 4.15.56, 4.16.44, 4.17.37, 4.18.20, 4.19.4
Red Hat Ceph Storage - update to 7.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins