Protection mechanism failure in Sudo - CVE-2025-32462
Published: July 1, 2025 / Updated: February 27, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient implementation of security measures when running sudo with -h (--host) option. If the current configuration provides access to users based on the host they are allowed to execute commands, a local user can bypass such a restriction by providing the hostname via the "-h" option they are allowed to execute commands. The vulnerability affects systems that use a common sudoers file that is distributed to multiple machines or when LDAP-based sudoers (including SSSD) is used.
Affected software
Red Hat OpenShift Container Platform
Debian Linux
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
macOS
Fedora
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Financial Transaction Manager for RedHat OpenShift
Business Automation Insights
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
app-admin/sudo
sudo (Ubuntu package)
sudo-devel
sudo
sudo (Red Hat package)
sudo-debuginfo
sudo-debugsource
sudo-help
sudo (Debian package)
sudo-python-plugin
sudo-logsrvd
Red Hat Ceph Storage
How to mitigate CVE-2025-32462
Netcool Operations Insight - update to 1.6.15
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
macOS - update to 26.1 25B78
app-admin/sudo - update to 1.8.5
sudo (Ubuntu package) - addressed in versions 1.8.9p5-1ubuntu1.5+esm8, 1.8.16-0ubuntu1.10+esm3, 1.8.21p2-3ubuntu1.6+esm1, 1.8.31-1ubuntu1.5+esm1, 1.9.9-1ubuntu2.5, 1.9.15p5-3ubuntu5.24.04.1, 1.9.15p5-3ubuntu5.24.10.1, 1.9.16p2-1ubuntu1.1
sudo-devel - addressed in versions 1.8.23-10, 1.9.15p5-3
sudo - addressed in versions 1.8.23-10, 1.9.5p2-1.0.1, 1.9.15p5-3
sudo (Red Hat package) - addressed in versions 1.8.23-10.el7_9.4, 1.8.29-5.el8_2.3, 1.8.29-7.el8_4.3, 1.9.5p2-1.el8_6.1, 1.9.5p2-1.el8_8.1, 1.9.5p2-1.el8_10.1, 1.9.5p2-7.el9_0.5, 1.9.5p2-9.el9_2.3, 1.9.5p2-10.el9_4.1, 1.9.5p2-10.el9_6.1, 1.9.15-8.p5.el10_0.2
sudo - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-debuginfo - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-debugsource - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-devel - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo-help - addressed in versions 1.9.2-18, 1.9.8p2-19, 1.9.15p5-4
sudo (Debian package) - update to 1.9.13p3-1+deb12u2
sudo-python-plugin - update to 1.9.15p5-3
sudo-logsrvd - update to 1.9.15p5-3
sudo - addressed in versions 1.9.17-2.p1.fc41, 1.9.17-2.p1.fc42
Red Hat OpenShift Container Platform - addressed in versions 4.12.79, 4.13.60, 4.14.55, 4.15.56, 4.16.44, 4.17.37, 4.18.20, 4.19.4
Red Hat Ceph Storage - update to 7.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Sudo
- Debian update for sudo
- Red Hat Enterprise Linux 9 update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Gentoo update for sudo
- Ubuntu update for sudo
- Ubuntu update for sudo
- Anolis OS update for sudo
- openEuler 20.03 LTS SP4 update for sudo
- openEuler 24.03 LTS SP1 update for sudo
- openEuler 24.03 LTS update for sudo
- openEuler 22.03 LTS SP4 update for sudo
- openEuler 22.03 LTS SP3 update for sudo
- Fedora 42 update for sudo
- Fedora 41 update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 9 update for sudo
- Red Hat Enterprise Linux 9 update for sudo
- openEuler 24.03 LTS SP2 update for sudo
- Red Hat Enterprise Linux 9 update for sudo
- Red Hat Enterprise Linux 8 update for sudo
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for sudo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Anolis OS update for sudo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Red Hat Enterprise Linux 10 update for sudo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Meinberg LANTIME firmware
- IBM Power Hardware Management Console (HMC) update for Sudo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Netcool Operations Insight
- Anolis OS update for sudo