#VU112066 Protection mechanism failure in Sudo - CVE-2025-32463
Published: July 1, 2025 / Updated: September 24, 2025
Sudo
Sudo
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient implementation of security measures when running sudo with -R (--chroot) option. A local user can run arbitrary commands as root, even if they are not listed in the sudoers file.
Note, the vulnerability affects installations with Name Service Switch (NSS) enabled.