The officially official Devuan Forum!

You are not logged in.

#1 2025-10-08 18:59:43

greenjeans
Member
Registered: 2017-04-07
Posts: 1,210  
Website

Critical security flaw in sudo

https://thehackernews.com/2025/09/cisa- … -flaw.html

"Sudo contains an inclusion of functionality from an untrusted control sphere vulnerability," CISA said. "This vulnerability could allow a local attacker to leverage sudo's -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file."

Great, I don't even use sudo and it's STILL a security risk.


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#2 2025-10-08 19:16:22

golinux
Administrator
Registered: 2016-11-25
Posts: 3,557  

Re: Critical security flaw in sudo

Great, I don't even use sudo and it's STILL a security risk.

Me too . . . sad

Offline

#3 2025-10-08 19:44:32

Altoid
Member
Registered: 2017-05-07
Posts: 1,855  

Re: Critical security flaw in sudo

Hello:

greenjeans wrote:

... a security risk.

Yes, it is.

But it is a local privilege escalation and (for now) it only affects sudo 1.9.14 to 1.9.17.

See here: https://gbhackers.com/poc-published-for … e-to-root/

gbhackers.com wrote:

... legacy versions prior to 1.9.14 remain unaffected since the vulnerable chroot feature did not exist in earlier releases.

I wonder what happened to do one thing and do it well?

That said, my up-to-date Devuan Daedalus (and yours) runs 1.9.13p3:

$ apt list | grep installed | grep sudo
--- snip ---
sudo/stable,stable-security,now 1.9.13p3-1+deb12u2 amd64 [installed]
$ 

So ...
Stay the course, everything wil be back to normal soon.

Best,

A.

Last edited by Altoid (2025-10-08 20:11:19)

Offline

#4 2025-10-08 20:03:08

golinux
Administrator
Registered: 2016-11-25
Posts: 3,557  

Re: Critical security flaw in sudo

@Altoid . . . I did not write that quote. greenjeans did . . . .l;

Offline

#5 2025-10-08 20:06:56

greenjeans
Member
Registered: 2017-04-07
Posts: 1,210  
Website

Re: Critical security flaw in sudo

This is what I really like about Altoid, always a voice of reasonableness in a sea of chaos. wink Cheers buddy!


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#6 2025-10-08 20:15:20

Altoid
Member
Registered: 2017-05-07
Posts: 1,855  

Re: Critical security flaw in sudo

Hello:

golinux wrote:

... did not write that quote.

Hmm ....
What'chu talkin' 'bout, Willis?

Oh, right ...
Taken care of.

Best,

A.

Offline

#7 2025-10-08 20:18:15

golinux
Administrator
Registered: 2016-11-25
Posts: 3,557  

Re: Critical security flaw in sudo

Hehehehe . . . maybe more coffee? big_smile

Offline

#8 2025-10-08 20:23:22

Altoid
Member
Registered: 2017-05-07
Posts: 1,855  

Re: Critical security flaw in sudo

Hello:

greenjeans wrote:

... reasonableness in a sea of chaos.

Nah ...
It was a fluke.

Probably remembered to take the green one this morning.
Or was it the red one? Can't recall.

That said, what's wrong with the proven and reliable chroot that it now has to have such a useful feature?
It never ends, does it?

Best,

A.

Offline

#9 2025-10-08 22:28:52

fsmithred
Administrator
Registered: 2016-11-25
Posts: 2,721  

Re: Critical security flaw in sudo

Fixed in trixie and forky/sid. (i.e. excalibur and freia/ceres) Older versions not affected.
https://security-tracker.debian.org/tra … 2025-32463

(I duck-searched the CVE with the words 'debian security' - first hit.)

Offline

#10 2025-10-09 04:08:54

stargate-sg1-cheyenne-mtn
Member
Registered: 2023-11-27
Posts: 381  

Re: Critical security flaw in sudo

@All, thanks for the timely rundown. visited the webpage @fsmithred linked and figured while i had the tab open i would slip in a little xkcd enjoyment...

so

enjoy

keyword(s): sudo make me a sandwich & santa claus naughty list


Be Excellent to each other and Party On!
https://www.youtube.com/watch?v=rph_1DODXDU
https://en.wikipedia.org/wiki/Bill_%26_Ted%27s_Excellent_Adventure
Do unto others as you would have them do instantaneously back to you!

Offline

#11 2025-10-09 14:50:36

greenjeans
Member
Registered: 2017-04-07
Posts: 1,210  
Website

Re: Critical security flaw in sudo

^^ I literally have a T-shirt with the sudo make me a sandwich cartoon on it, found it in a secondhand store years ago.


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#12 Yesterday 05:34:07

zapper
Member
Registered: 2017-05-29
Posts: 1,134  

Re: Critical security flaw in sudo

I prefer doas myself to be honest.  It is much less complicated but still has the functionality I need in sudo/su.

I use that even on devuan/gnuinos


Freedom is never more than one generation away from extinction. Feelings are not facts
If you wish to be humbled, try to exalt yourself long term  If you wish to be exalted, try to humble yourself long term
Favourite operating systems: Hyperbola Devuan OpenBSD
Peace Be With us All!

Offline

Board footer