▲ 70 ▼ CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems (thehackernews.com) submitted 10 months ago by kid@sh.itjust.works [M] to c/cybersecurity@sh.itjust.works 13 comments fedilink hide all child comments
[–] perishthethought@piefed.social 9 points 10 months ago (3 children) On Ubuntu 24.04 Sudo version 1.9.15p5 Eep! permalink fedilink source parent hideshow 6 child comments replies: [–] sem@lemmy.blahaj.zone 4 points 10 months ago (1 child) Wait, shouldn't Ubuntu 24.04 LTS get security bugfixes? permalink fedilink source parent hideshow 2 child comments replies: [–] SSUPII@sopuli.xyz 3 points 10 months ago It does. In fact it is fixed. All decent LTS/stable distros will cherrypick security fixes into whatever version they stabilized themselves on. permalink fedilink source parent [–] GJdan@programming.dev 3 points 10 months ago* It should be backported in supported ubuntu versions. sudo apt changelog sudo Tap for spoiler sudo (1.9.15p5-3ubuntu5.24.04.1) noble-security; urgency=medium SECURITY UPDATE: Local Privilege Escalation via host option debian/patches/CVE-2025-32462.patch: only allow specifying a host when listing privileges. CVE-2025-32462 SECURITY UPDATE: Local Privilege Escalation via chroot option debian/patches/CVE-2025-32463.patch: remove user-selected root directory chroot option. CVE-2025-32463 -- Marc Deslauriers marc.deslauriers@ubuntu.com Wed, 25 Jun 2025 08:42:53 -0400 permalink fedilink source parent [–] fmstrat@lemmy.nowsci.com 3 points 10 months ago p5. The patch was backported. permalink fedilink source parent
[–] sem@lemmy.blahaj.zone 4 points 10 months ago (1 child) Wait, shouldn't Ubuntu 24.04 LTS get security bugfixes? permalink fedilink source parent hideshow 2 child comments replies: [–] SSUPII@sopuli.xyz 3 points 10 months ago It does. In fact it is fixed. All decent LTS/stable distros will cherrypick security fixes into whatever version they stabilized themselves on. permalink fedilink source parent
[–] SSUPII@sopuli.xyz 3 points 10 months ago It does. In fact it is fixed. All decent LTS/stable distros will cherrypick security fixes into whatever version they stabilized themselves on. permalink fedilink source parent
[–] GJdan@programming.dev 3 points 10 months ago* It should be backported in supported ubuntu versions. sudo apt changelog sudo Tap for spoiler sudo (1.9.15p5-3ubuntu5.24.04.1) noble-security; urgency=medium SECURITY UPDATE: Local Privilege Escalation via host option debian/patches/CVE-2025-32462.patch: only allow specifying a host when listing privileges. CVE-2025-32462 SECURITY UPDATE: Local Privilege Escalation via chroot option debian/patches/CVE-2025-32463.patch: remove user-selected root directory chroot option. CVE-2025-32463 -- Marc Deslauriers marc.deslauriers@ubuntu.com Wed, 25 Jun 2025 08:42:53 -0400 permalink fedilink source parent
[–] fmstrat@lemmy.nowsci.com 3 points 10 months ago p5. The patch was backported. permalink fedilink source parent