<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:43:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11537 — Important: sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11537</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sudo, AlmaLinux:10: sudo-python-plugin&lt;/p&gt;
&lt;p&gt;The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sudo: LPE via host option (CVE-2025-32462)
  * sudo: LPE via chroot option (CVE-2025-32463)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sudo, AlmaLinux:10: sudo-python-plugin&lt;/p&gt;
&lt;p&gt;The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sudo: LPE via host option (CVE-2025-32462)
  * sudo: LPE via chroot option (CVE-2025-32463)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11537</guid>
    </item>
    <item>
      <title>bdu:2025-07765</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07765</link>
      <description>bdu:2025-07765</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07765</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-32463</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-32463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: sudo, Alpaquita:25: sudo, Alpaquita:stream: sudo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: sudo, Alpaquita:25: sudo, Alpaquita:stream: sudo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-32463</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-272596</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-272596</link>
      <description>EUVD-2026-272596</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-272596</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32463</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32463</link>
      <description>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32463</guid>
    </item>
    <item>
      <title>GHSA-695j-c63m-mvxc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-695j-c63m-mvxc</link>
      <description>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-695j-c63m-mvxc</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-32463 — Sudo before 1.9.17p1 allows local users to obtain root access</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32463</link>
      <description>msrc_CVE-2025-32463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-32463</guid>
    </item>
    <item>
      <title>OESA-2025-1735 — sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.(CVE-2025-32462)&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 (Operating System Utility Software) and classified as critical.The manipulation of the argument -R/--chroot with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.As an impact it is known to affect confidentiality, integrity, and availability.Applying the patch 1.9.17p1 is able to eliminate this problem.(CVE-2025-32463)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.(CVE-2025-32462)&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 (Operating System Utility Software) and classified as critical.The manipulation of the argument -R/--chroot with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.As an impact it is known to affect confidentiality, integrity, and availability.Applying the patch 1.9.17p1 is able to eliminate this problem.(CVE-2025-32463)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1735</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15298-1 — sudo-1.9.17p1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15298-1</link>
      <description>&lt;p&gt;sudo-1.9.17p1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo-1.9.17p1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15298-1</guid>
    </item>
    <item>
      <title>RHSA-2025:11537 — Red Hat Security Advisory: sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11537</link>
      <description>&lt;p&gt;sudo: LPE via host option sudo: LPE via chroot option&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo: LPE via host option sudo: LPE via chroot option&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11537</guid>
    </item>
    <item>
      <title>SCA-2025-0012 — Sudo vulnerability affects SICK SID products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0012</link>
      <description>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0012</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:20478-1 — Security update for sudo</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:20478-1</link>
      <description>&lt;p&gt;Security update for sudo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sudo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:20478-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-32463</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32463</guid>
    </item>
    <item>
      <title>VDE-2025-082 — WAGO: Critical sudo Vulnerability in Multiple Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-082</link>
      <description>&lt;p&gt;A vulnerability in sudo allows a low privileged attacker to execute commands with root rights.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in sudo allows a low privileged attacker to execute commands with root rights.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-082</guid>
    </item>
    <item>
      <title>VDE-2026-032 — Endress+Hauser: sudo vulnerability affects Endress+Hauser MCS200HW</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-032</link>
      <description>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-032</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1428 — sudo: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1428</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in sudo ausnutzen, um Sicherheitsvorkehrungen zu umgehen und seine Rechte auf &amp;#34;root&amp;#34; zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in sudo ausnutzen, um Sicherheitsvorkehrungen zu umgehen und seine Rechte auf &amp;#34;root&amp;#34; zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1428</guid>
    </item>
  </channel>
</rss>
