In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sudo | Sudo_project | * | 1.9.17 (excluding) |
| Sudo | Sudo_project | 1.9.17 (including) | 1.9.17 (including) |
| Sudo | Sudo_project | 1.9.17-p1 (including) | 1.9.17-p1 (including) |
| Sudo | Sudo_project | 1.9.17-p2 (including) | 1.9.17-p2 (including) |
| Red Hat Enterprise Linux 10 | RedHat | sudo-0:1.9.15-10.p5.el10_1 | * |
| Red Hat Enterprise Linux 10 | RedHat | sudo-0:1.9.17-4.p2.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | sudo-0:1.9.15-8.p5.el10_0.3 | * |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | RedHat | sudo-0:1.8.6p3-29.el6_10.8 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | sudo-0:1.8.23-10.el7_9.5 | * |
| Red Hat Enterprise Linux 8 | RedHat | sudo-0:1.9.5p2-1.el8_10.5 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | sudo-0:1.9.5p2-1.el8_6.3 | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | sudo-0:1.9.5p2-1.el8_6.3 | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | sudo-0:1.9.5p2-1.el8_6.3 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | sudo-0:1.9.5p2-1.el8_8.3 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | sudo-0:1.9.5p2-1.el8_8.3 | * |
| Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.5p2-15.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.17p2-3.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.5p2-15.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.17p2-3.el9_8 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | sudo-0:1.9.5p2-7.el9_0.6 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | sudo-0:1.9.5p2-9.el9_2.4 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | sudo-0:1.9.5p2-10.el9_4.3 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | sudo-0:1.9.5p2-10.el9_6.3 | * |
| Red Hat OpenShift Container Platform 4.12 | RedHat | rhcos-412.86.202605271418-0 | * |
| Red Hat OpenShift Container Platform 4.13 | RedHat | rhcos-413.92.202605271328-0 | * |
| Red Hat OpenShift Container Platform 4.15 | RedHat | rhcos-415.92.202606030318-0 | * |
| Red Hat OpenShift Container Platform 4.16 | RedHat | rhcos-416.94.202605200242-0 | * |
| Red Hat OpenShift Container Platform 4.18 | RedHat | rhcos-418.94.202605260517-0 | * |
| Red Hat OpenShift Container Platform 4.19 | RedHat | rhcos-4.19.9.6.202605201155-0 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1779798165 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1779798222 | * |
| Sudo | Ubuntu | devel | * |
| Sudo | Ubuntu | jammy | * |
| Sudo | Ubuntu | noble | * |
| Sudo | Ubuntu | questing | * |
| Sudo | Ubuntu | upstream | * |