<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:03:42.199260+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11537</id>
    <title>ALSA-2025:11537 — Important: sudo security update</title>
    <updated>2026-10-02T10:03:42.438044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: sudo, AlmaLinux:10: sudo-python-plugin</p>
<p>The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.</p>
<p>Security Fix(es):</p>
<p>* sudo: LPE via host option (CVE-2025-32462)
  * sudo: LPE via chroot option (CVE-2025-32463)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07765</id>
    <title>bdu:2025-07765</title>
    <updated>2026-10-02T10:03:42.438110+00:00</updated>
    <content>bdu:2025-07765</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-32463</id>
    <title>BELL-CVE-2025-32463</title>
    <updated>2026-10-02T10:03:42.438128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: sudo, Alpaquita:25: sudo, Alpaquita:stream: sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-32463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T10:03:42.438149+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272596</id>
    <title>EUVD-2026-272596</title>
    <updated>2026-10-02T10:03:42.438165+00:00</updated>
    <content>EUVD-2026-272596</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32463</id>
    <title>fkie_cve-2025-32463</title>
    <updated>2026-10-02T10:03:42.438176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-695j-c63m-mvxc</id>
    <title>GHSA-695j-c63m-mvxc</title>
    <updated>2026-10-02T10:03:42.438196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-695j-c63m-mvxc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32463</id>
    <title>msrc_CVE-2025-32463 — Sudo before 1.9.17p1 allows local users to obtain root access</title>
    <updated>2026-10-02T10:03:42.438209+00:00</updated>
    <content>msrc_CVE-2025-32463</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-32463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1735</id>
    <title>OESA-2025-1735 — sudo security update</title>
    <updated>2026-10-02T10:03:42.438225+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: sudo</p>
<p>Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.

Security Fix(es):</p>
<p>Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.(CVE-2025-32462)</p>
<p>A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 (Operating System Utility Software) and classified as critical.The manipulation of the argument -R/--chroot with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.As an impact it is known to affect confidentiality, integrity, and availability.Applying the patch 1.9.17p1 is able to eliminate this problem.(CVE-2025-32463)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15298-1</id>
    <title>openSUSE-SU-2025:15298-1 — sudo-1.9.17p1-1.1 on GA media</title>
    <updated>2026-10-02T10:03:42.438252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo-1.9.17p1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15298-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11537</id>
    <title>RHSA-2025:11537 — Red Hat Security Advisory: sudo security update</title>
    <updated>2026-10-02T10:03:42.438269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo: LPE via host option sudo: LPE via chroot option</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2025-0012</id>
    <title>SCA-2025-0012 — Sudo vulnerability affects SICK SID products</title>
    <updated>2026-10-02T10:03:42.438286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2025-0012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:20478-1</id>
    <title>SUSE-SU-2025:20478-1 — Security update for sudo</title>
    <updated>2026-10-02T10:03:42.438301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:20478-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32463</id>
    <title>UBUNTU-CVE-2025-32463</title>
    <updated>2026-10-02T10:03:42.438314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: sudo</p>
<p>Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-082</id>
    <title>VDE-2025-082 — WAGO: Critical sudo Vulnerability in Multiple Products</title>
    <updated>2026-10-02T10:03:42.438329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in sudo allows a low privileged attacker to execute commands with root rights.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-032</id>
    <title>VDE-2026-032 — Endress+Hauser: sudo vulnerability affects Endress+Hauser MCS200HW</title>
    <updated>2026-10-02T10:03:42.438343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1428</id>
    <title>WID-SEC-W-2025-1428 — sudo: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:03:42.438357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in sudo ausnutzen, um Sicherheitsvorkehrungen zu umgehen und seine Rechte auf "root" zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1428"/>
  </entry>
</feed>
