<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:38:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-239005</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239005</link>
      <description>EUVD-2026-239005</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239005</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46718</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46718</link>
      <description>&lt;p&gt;sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46718</guid>
    </item>
    <item>
      <title>GHSA-w9q3-g4p5-5q2r — sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w9q3-g4p5-5q2r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sudo-rs&lt;/p&gt;
&lt;p&gt;### Summary
Users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This doesn&amp;#39;t happen with the original sudo.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The initial test has been done in a container running Ubuntu 24.04 and installing [oxidizr](https://github.com/jnsgruk/oxidizr), running sudo-rs 0.2.2.&lt;/p&gt;
&lt;p&gt;A user (bob) has been added with only ps command executable through sudo:&lt;/p&gt;
&lt;p&gt;```
root    ALL=(ALL:ALL) ALL
bob     ALL=(ALL:ALL) /usr/bin/ps
```&lt;/p&gt;
&lt;p&gt;The user is not able to read the `/etc/sudoers` file and running `sudo -l -Uroot` with original sudo (version 1.9.15p5) causes the following error:&lt;/p&gt;
&lt;p&gt;```
Sorry, user bob is not allowed to execute &amp;#39;list&amp;#39; as root on 43d4aed3cdbd.
```&lt;/p&gt;
&lt;p&gt;The same command with sudo-rs is run without denying the execution:&lt;/p&gt;
&lt;p&gt;```
User root may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) ALL
```&lt;/p&gt;
&lt;p&gt;The same happens for other non-root users:&lt;/p&gt;
&lt;p&gt;```
bob@43d4aed3cdbd:~$ sudo -l -Ufoo
User foo may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) /usr/bin/whoami
```&lt;/p&gt;
&lt;p&gt;The behavior has been also been observed for version 0.2.5.&lt;/p&gt;
&lt;p&gt;### Impact
Users with limited sudo privileges can enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks.&lt;/p&gt;
&lt;p&gt;Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sudo-rs&lt;/p&gt;
&lt;p&gt;### Summary
Users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This doesn&amp;#39;t happen with the original sudo.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The initial test has been done in a container running Ubuntu 24.04 and installing [oxidizr](https://github.com/jnsgruk/oxidizr), running sudo-rs 0.2.2.&lt;/p&gt;
&lt;p&gt;A user (bob) has been added with only ps command executable through sudo:&lt;/p&gt;
&lt;p&gt;```
root    ALL=(ALL:ALL) ALL
bob     ALL=(ALL:ALL) /usr/bin/ps
```&lt;/p&gt;
&lt;p&gt;The user is not able to read the `/etc/sudoers` file and running `sudo -l -Uroot` with original sudo (version 1.9.15p5) causes the following error:&lt;/p&gt;
&lt;p&gt;```
Sorry, user bob is not allowed to execute &amp;#39;list&amp;#39; as root on 43d4aed3cdbd.
```&lt;/p&gt;
&lt;p&gt;The same command with sudo-rs is run without denying the execution:&lt;/p&gt;
&lt;p&gt;```
User root may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) ALL
```&lt;/p&gt;
&lt;p&gt;The same happens for other non-root users:&lt;/p&gt;
&lt;p&gt;```
bob@43d4aed3cdbd:~$ sudo -l -Ufoo
User foo may run the following commands on 43d4aed3cdbd:
    (ALL : ALL) /usr/bin/whoami
```&lt;/p&gt;
&lt;p&gt;The behavior has been also been observed for version 0.2.5.&lt;/p&gt;
&lt;p&gt;### Impact
Users with limited sudo privileges can enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks.&lt;/p&gt;
&lt;p&gt;Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w9q3-g4p5-5q2r</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-46718</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46718</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: rust-sudo-rs, Ubuntu:25.10: rust-sudo-rs&lt;/p&gt;
&lt;p&gt;sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: rust-sudo-rs, Ubuntu:25.10: rust-sudo-rs&lt;/p&gt;
&lt;p&gt;sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users&amp;#39; permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46718</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1043 — sudo-rs: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1043</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in sudo-rs ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in sudo-rs ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1043</guid>
    </item>
  </channel>
</rss>
