FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

sudo -- privilege escalation vulnerability through host and chroot options

Affected packages
sudo < 1.9.17p1
sudo-sssd < 1.9.17p1

Details

VuXML ID 24f4b495-56a1-11f0-9621-93abbef07693
Discovery 2025-04-01
Entry 2025-07-01

Todd C. Miller reports, crediting Rich Mirch from Stratascale Cyber Research Unit (CRU):

Sudo 1.9.17p1:

References

CVE Name CVE-2025-32462
CVE Name CVE-2025-32463
URL https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host
URL https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
URL https://www.sudo.ws/releases/stable/