The officially official Devuan Forum!

You are not logged in.

#1 2025-10-08 18:59:43

greenjeans
Member
Registered: 2017-04-07
Posts: 1,227  
Website

Critical security flaw in sudo

https://thehackernews.com/2025/09/cisa- … -flaw.html

"Sudo contains an inclusion of functionality from an untrusted control sphere vulnerability," CISA said. "This vulnerability could allow a local attacker to leverage sudo's -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file."

Great, I don't even use sudo and it's STILL a security risk.


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#2 2025-10-08 19:16:22

golinux
Administrator
Registered: 2016-11-25
Posts: 3,568  

Re: Critical security flaw in sudo

Great, I don't even use sudo and it's STILL a security risk.

Me too . . . sad

Online

#3 2025-10-08 19:44:32

Altoid
Member
Registered: 2017-05-07
Posts: 1,861  

Re: Critical security flaw in sudo

Hello:

greenjeans wrote:

... a security risk.

Yes, it is.

But it is a local privilege escalation and (for now) it only affects sudo 1.9.14 to 1.9.17.

See here: https://gbhackers.com/poc-published-for … e-to-root/

gbhackers.com wrote:

... legacy versions prior to 1.9.14 remain unaffected since the vulnerable chroot feature did not exist in earlier releases.

I wonder what happened to do one thing and do it well?

That said, my up-to-date Devuan Daedalus (and yours) runs 1.9.13p3:

$ apt list | grep installed | grep sudo
--- snip ---
sudo/stable,stable-security,now 1.9.13p3-1+deb12u2 amd64 [installed]
$ 

So ...
Stay the course, everything wil be back to normal soon.

Best,

A.

Last edited by Altoid (2025-10-08 20:11:19)

Offline

#4 2025-10-08 20:03:08

golinux
Administrator
Registered: 2016-11-25
Posts: 3,568  

Re: Critical security flaw in sudo

@Altoid . . . I did not write that quote. greenjeans did . . . .l;

Online

#5 2025-10-08 20:06:56

greenjeans
Member
Registered: 2017-04-07
Posts: 1,227  
Website

Re: Critical security flaw in sudo

This is what I really like about Altoid, always a voice of reasonableness in a sea of chaos. wink Cheers buddy!


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#6 2025-10-08 20:15:20

Altoid
Member
Registered: 2017-05-07
Posts: 1,861  

Re: Critical security flaw in sudo

Hello:

golinux wrote:

... did not write that quote.

Hmm ....
What'chu talkin' 'bout, Willis?

Oh, right ...
Taken care of.

Best,

A.

Offline

#7 2025-10-08 20:18:15

golinux
Administrator
Registered: 2016-11-25
Posts: 3,568  

Re: Critical security flaw in sudo

Hehehehe . . . maybe more coffee? big_smile

Online

#8 2025-10-08 20:23:22

Altoid
Member
Registered: 2017-05-07
Posts: 1,861  

Re: Critical security flaw in sudo

Hello:

greenjeans wrote:

... reasonableness in a sea of chaos.

Nah ...
It was a fluke.

Probably remembered to take the green one this morning.
Or was it the red one? Can't recall.

That said, what's wrong with the proven and reliable chroot that it now has to have such a useful feature?
It never ends, does it?

Best,

A.

Offline

#9 2025-10-08 22:28:52

fsmithred
Administrator
Registered: 2016-11-25
Posts: 2,731  

Re: Critical security flaw in sudo

Fixed in trixie and forky/sid. (i.e. excalibur and freia/ceres) Older versions not affected.
https://security-tracker.debian.org/tra … 2025-32463

(I duck-searched the CVE with the words 'debian security' - first hit.)

Offline

#10 2025-10-09 04:08:54

stargate-sg1-cheyenne-mtn
Member
Registered: 2023-11-27
Posts: 392  

Re: Critical security flaw in sudo

@All, thanks for the timely rundown. visited the webpage @fsmithred linked and figured while i had the tab open i would slip in a little xkcd enjoyment...

so

enjoy

keyword(s): sudo make me a sandwich & santa claus naughty list


Be Excellent to each other and Party On!
https://www.youtube.com/watch?v=rph_1DODXDU
https://en.wikipedia.org/wiki/Bill_%26_Ted%27s_Excellent_Adventure
Do unto others as you would have them do instantaneously back to you!

Offline

#11 2025-10-09 14:50:36

greenjeans
Member
Registered: 2017-04-07
Posts: 1,227  
Website

Re: Critical security flaw in sudo

^^ I literally have a T-shirt with the sudo make me a sandwich cartoon on it, found it in a secondhand store years ago.


https://sourceforge.net/projects/vuu-do/ New Vuu-do isos uploaded October 2025!
Vuu-do GNU/Linux, minimal Devuan-based Openbox and Mate systems to build on. Also a max version for OB.
Devuan 5 mate-mini iso, pure Devuan, 100% no-vuu-do. wink Devuan 6 version also available for testing.
Please donate to support Devuan and init freedom! https://devuan.org/os/donate

Offline

#12 2025-10-10 05:34:07

zapper
Member
Registered: 2017-05-29
Posts: 1,137  

Re: Critical security flaw in sudo

I prefer doas myself to be honest.  It is much less complicated but still has the functionality I need in sudo/su.

I use that even on devuan/gnuinos

With jwmkit combined with doas, I can shutdown properly or poweroff properly.

I cannot make heads or tails on how to do the same thing with sudo lol. There is just too much to sort out  in that  sudoers file

xD

Last edited by zapper (2025-10-12 08:17:55)


Freedom is never more than one generation away from extinction. Feelings are not facts
If you wish to be humbled, try to exalt yourself long term  If you wish to be exalted, try to humble yourself long term
Favourite operating systems: Hyperbola Devuan OpenBSD
Peace Be With us All!

Offline

#13 2025-10-16 07:47:44

blackhole
Member
Registered: 2020-03-16
Posts: 150  

Re: Critical security flaw in sudo

These were fixed back in June: https://git.sudo.ws/sudo/commit/?id=23aff2b37

To add some much needed perspective:

https://www.cvedetails.com/vendor/15714/
https://www.cvedetails.com/vendor/33/Linux.html

Yet none here seem concerned about running the Linux kernel...

Last edited by blackhole (2025-10-16 08:13:30)

Offline

#14 Today 04:53:15

zapper
Member
Registered: 2017-05-29
Posts: 1,137  

Re: Critical security flaw in sudo

@blackhole I suppose that could be a risk as well.

Truthfully, most software has vulnerabilities unless it doesn't connect to something that doesn't do anything online.

Although I suppose it could be more indirect than that.


Freedom is never more than one generation away from extinction. Feelings are not facts
If you wish to be humbled, try to exalt yourself long term  If you wish to be exalted, try to humble yourself long term
Favourite operating systems: Hyperbola Devuan OpenBSD
Peace Be With us All!

Offline

Board footer