Executive brief
Sudo, a widely-used utility for running commands with elevated privileges, fails to enforce access controls when users invoke the execveat system call in ptrace-based monitoring mode. An attacker with permission to run specific commands can bypass policy restrictions and execute denied programs, circumventing logging and audit controls that organizations rely on to enforce least-privilege access.
Technical details
The vulnerability is a privilege escalation flaw in Sudo's ptrace-based intercept mode. The flaw exists in the exec_ptrace.c component, where policy checks are not applied to the execveat system call (and by extension, fexecve, which uses execveat internally). An authenticated user permitted to run certain commands can invoke execveat or fexecve to execute programs that the policy denies, bypassing the intercept policy enforcement and audit logging. The attack requires local access and that the attacker be already permitted to run some sudo commands. A patch is expected in versions after 1.9.17p2.
Affected products
- Sudo Project Sudo through 1.9.17p2
Timeline
- 2026-08-29: disclosed
- other: Known CVE as of publication