← Back

CVE-2025-32463

Published: Jun 30, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Affected (18)

Show all products
1 product
Sudo
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Leap
1 product
Enterprise Linux
3 products
Linux Enterprise Desktop
Linux Enterprise Real Time
Linux Enterprise Server For Sap
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sudo Project
From 1.9.14 to 1.9.17
Version 1.9.17
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 22.04
Version 24.04
Version 24.10
Version 25.04
Debian
Version 11.0
Version 12.0
Version 13.0
Version 15.6
Version 10.0
Suse
Version 15 sp6
Version 15 sp7
Suse
Version 15.0 sp2
Version 15.0 sp6
Version 15.0 sp7
Suse
Version 12 sp6
Version 12 sp7

References (17)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.