Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
High Listed in CISA KEV
Summary
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Sudo:Sudo
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-32463 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.sudo.ws/security/advisories/chroot_bug/ reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV