Major Linux Distros impacted: sudo vulnerabilities let local users get root access

watch 1m, 21s
views 2

13:52, 07.07.2025

Recently, two major vulnerabilities in the sudo command-line for Unix and Linux OSs were discovered. The issue is that a local user can get root privileges.

Description of the vulnerabilities

  • CVE-2025-32463. The root access can be received because "/etc/nsswitch.conf" from the user-control directory is with the –chroot option (Amazon, Debian, Gentoo, Alpine, SUSE, Ubuntu, and Red Hat).
  • CVE-2025-32462. With the sudoers file, which determines a host that isn’t ALL or current, it can allow some listed users to execute commands (AlmaLinux 8, AlmaLinux 9, Oracle Linux, and all distros that were mentioned in the above-discussed vulnerability).

With sudo, it is possible to have a low-privileged user and run commands with superuser rights. Generally, sudo functions according to the principle of the least privileges, and that means admin tasks can be done without the permission elevations for the specific user. This command is configured via "/etc/sudoers,".

The researcher who discovered the vulnerabilities mentioned that it is rooted in Sudo's "-h" (host) option. This feature has been available for 12 years already without any disclosure. With the help of this option, it is possible to list a user’s sudo privileges for different host.

Nevertheless, this vulnerability made it possible to execute any command that is allowed by the remote host. This can impact the websites that use a common sudoers file shared by various machines.

When talking about CVE-2025-32463, it can execute root commands even when not listed in sudoers.

Sudo version 1.9.17p1 was released without these vulnerabilities. Moreover, some recommendations for different Linux distros were shared. Users should apply fixes and check whether they have the latest package updates. 

Share

Was this article helpful to you?

VPS popular offers

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 2048 Linux

8.3 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
wKVM-SSD 4096 Windows

18.65 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 4096 Linux

15 /mo

/mo

Billed annually

-15.4%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
150 GB SSD
Bandwidth
Bandwidth
100 Mbps
DDoS Protected SSD-wKVM 16384 Windows

130 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Epyc Cores
RAM
RAM
16 GB
Space
Space
150 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 16384
OS
CentOS
Software
Software
Keitaro

55.54 /mo

/mo

Billed annually

-24.7%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
4 TB
KVM-SSD 4096 Metered Linux

31 /mo

/mo

Billed annually

-10%

CPU
CPU
3 Epyc Cores
RAM
RAM
2 GB
Space
Space
25 GB NVMe
Bandwidth
Bandwidth
Unlimited
wKVM-NVMe 2048 Windows

9.9 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Epyc Cores
RAM
RAM
8 GB
Space
Space
100 GB NVMe
Bandwidth
Bandwidth
Unlimited
KVM-NVMe 8192 Linux

26.35 /mo

/mo

Billed annually

-15.6%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
20 GB SSD
Bandwidth
Bandwidth
30 Mbps
DDoS Protected SSD-KVM 1024 Linux

38 /mo

/mo

Billed annually

-15.3%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
75 GB SSD
Bandwidth
Bandwidth
40 Mbps
DDoS Protected SSD-wKVM 2048 Windows

54 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.