<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:38:51.552486+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239005</id>
    <title>EUVD-2026-239005</title>
    <updated>2026-10-03T20:38:51.555724+00:00</updated>
    <content>EUVD-2026-239005</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46718</id>
    <title>fkie_cve-2025-46718</title>
    <updated>2026-10-03T20:38:51.555757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users' permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-46718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9q3-g4p5-5q2r</id>
    <title>GHSA-w9q3-g4p5-5q2r — sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others</title>
    <updated>2026-10-03T20:38:51.555792+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: sudo-rs</p>
<p>### Summary
Users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This doesn't happen with the original sudo.</p>
<p>### PoC</p>
<p>The initial test has been done in a container running Ubuntu 24.04 and installing [oxidizr](https://github.com/jnsgruk/oxidizr), running sudo-rs 0.2.2.</p>
<p>A user (bob) has been added with only ps command executable through sudo:</p>
<p>```
root    ALL=(ALL:ALL) ALL
bob     ALL=(ALL:ALL) /usr/bin/ps
```</p>
<p>The user is not able to read the `/etc/sudoers` file and running `sudo -l -Uroot` with original sudo (version 1.9.15p5) causes the following error:</p>
<p>```
Sorry, user bob is not allowed to execute 'list' as root on 43d4aed3cdbd.
```</p>
<p>The same command with sudo-rs is run without denying the execution:</p>
<p>```
User root may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) ALL
```</p>
<p>The same happens for other non-root users:</p>
<p>```
bob@43d4aed3cdbd:~$ sudo -l -Ufoo
User foo may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) /usr/bin/whoami
```</p>
<p>The behavior has been also been observed for version 0.2.5.</p>
<p>### Impact
Users with limited sudo privileges can enumerate the sudoers file, revealing sensitive information about other users' permissions. Attackers can collect information that can be used to more targeted attacks.</p>
<p>Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9q3-g4p5-5q2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46718</id>
    <title>UBUNTU-CVE-2025-46718</title>
    <updated>2026-10-03T20:38:51.555840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: rust-sudo-rs, Ubuntu:25.10: rust-sudo-rs</p>
<p>sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users' permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1043</id>
    <title>WID-SEC-W-2025-1043 — sudo-rs: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-03T20:38:51.555866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in sudo-rs ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1043"/>
  </entry>
</feed>
