Debian alert DLA-4614-1 (sudo)
| From: | Andreas Henriksson <andreas@fatal.se> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4614-1] sudo security update | |
| Date: | Thu, 04 Jun 2026 13:57:11 +0200 | |
| Message-ID: | <kui6wxcv36mvkeqm3ylqyu3wz2xek5acwr6xoxoyrqjtptviby@m4fz2tpi3r7e> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson June 04, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sudo Version : 1.9.5p2-3+deb11u4 CVE ID : CVE-2026-35535 Debian Bug : 1130593 Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.5p2-3+deb11u4. We recommend that you upgrade your sudo packages. For the detailed security status of sudo please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sudo Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmohaBUACgkQC8R9xk0T UwZVwRAAjhjA6hXhnHrj7RjIDJSAh7nciIJmH7ZXtMIewyKtb50ehF/YjgKpSCGD wVpExARtfeb3jOLvJAEIyR7k/NgOrb5cDOq8S6sq7URHUTp9n1eP1J8PAmXhipwN eHPH4SWzfvibxVTwBllJXC5Kdtza19w1lq5Vd/w0FKqBhsicatxP2Lr6tWFETsDF I6GFZBBs2nhTn/V0kksgWN1WFpcBXxjvwUIp9ClQxIZBX55ReAJbmzPoOo5ed060 PAi45KZdRiB8Ernn8HbnCOxnSY8XX1XxnM+6aOw36H9cax4ZysE0rqunrsGY8Uf1 LZ6Ze5CiQpH9B9JzrH2G1J1eev2Vu/P3n28CC9z8+TkanJSpLgwXxAwjTnBI8BJc 6OofMRRo/qzIylV0oe6ZjiBnhC5IgDW3aaFcHmkPMQqDw2nCYI1vdnxQ+93v4dE+ jI6p3cC9m11bneEOAqSxLscvp1IZX98E8ED5YAEscAWNG8s6cKXc8zkKYsIQg0H8 gEzLX+08n57K+cFwGRcQjhtbMP1BmWWz1s324v4A0f2HKrcn4XbZTj3uLOI8kmyK bd4j8/bRqYCTmHb7e94RabR3r3hADUCFMpxs0pRroHmtnnm0KC+tXCKT9hC94d6w IPJQDUFWrPrbzaP9wGBiB8agSgm22dvsygT11+X4kSA39fRqgQI= =iSeV -----END PGP SIGNATURE-----
