Major Linux Distros impacted: sudo vulnerabilities let local users get root access

watch 1m, 21s
views 2

13:52, 07.07.2025

Recently, two major vulnerabilities in the sudo command-line for Unix and Linux OSs were discovered. The issue is that a local user can get root privileges.

Description of the vulnerabilities

  • CVE-2025-32463. The root access can be received because "/etc/nsswitch.conf" from the user-control directory is with the –chroot option (Amazon, Debian, Gentoo, Alpine, SUSE, Ubuntu, and Red Hat).
  • CVE-2025-32462. With the sudoers file, which determines a host that isn’t ALL or current, it can allow some listed users to execute commands (AlmaLinux 8, AlmaLinux 9, Oracle Linux, and all distros that were mentioned in the above-discussed vulnerability).

With sudo, it is possible to have a low-privileged user and run commands with superuser rights. Generally, sudo functions according to the principle of the least privileges, and that means admin tasks can be done without the permission elevations for the specific user. This command is configured via "/etc/sudoers,".

The researcher who discovered the vulnerabilities mentioned that it is rooted in Sudo's "-h" (host) option. This feature has been available for 12 years already without any disclosure. With the help of this option, it is possible to list a user’s sudo privileges for different host.

Nevertheless, this vulnerability made it possible to execute any command that is allowed by the remote host. This can impact the websites that use a common sudoers file shared by various machines.

When talking about CVE-2025-32463, it can execute root commands even when not listed in sudoers.

Sudo version 1.9.17p1 was released without these vulnerabilities. Moreover, some recommendations for different Linux distros were shared. Users should apply fixes and check whether they have the latest package updates. 

Share

Was this article helpful to you?

VPS popular offers

-10%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
200 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 8192 Linux

25.25 /mo

/mo

Billed annually

-10%

CPU
CPU
2 Epyc Cores
RAM
RAM
1 GB
Space
Space
10 GB NVMe
Bandwidth
Bandwidth
Unlimited
KVM-NVMe 1024 Linux

7.2 /mo

/mo

Billed annually

CPU
CPU
8 Epyc Cores
RAM
RAM
32 GB
Space
Space
200 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 32768
OS
CentOS
Software
Software
Keitaro
/mo

Billed annually

-22.2%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
300 GB
KVM-SSD 4096 HK Linux

33 /mo

/mo

Billed annually

-7.1%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB HDD
Bandwidth
Bandwidth
Unlimited
wKVM-HDD 4096 Windows

21 /mo

/mo

Billed annually

-8.1%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
wKVM-SSD 8192 Windows

31.9 /mo

/mo

Billed annually

CPU
CPU
6 Epyc Cores
RAM
RAM
8 GB
Space
Space
100 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 8192
OS
CentOS
Software
Software
Keitaro
/mo

Billed annually

-5.3%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
60 GB HDD
Bandwidth
Bandwidth
300 Gb
wKVM-HDD HK 2048 Windows

11.68 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 8192 Linux

25.85 /mo

/mo

Billed annually

-16.3%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
40 Mbps
DDoS Protected SSD-KVM 2048 Linux

48 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.