Back Linuxsecurity Ubuntu 26.04 LTS sudo-rs Important Privilege Escalation Issue USN-8708
Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×
sudo-rs could be made to run programs as an administrator. Software Description: - rust-sudo-rs: Rust-based sudo and su implementations Details: It was discovered that sudo-rs incorrectly handled time-of-check vs time- of-use conditions in sudoedit. A local attacker with permission to edit specific files using sudoedit could use this issue to place files in arbitrary directories, and possibly escalate their privileges. This issue only affected systems configured to grant fine-grained sudoedit file editing permissions, which is not the default configuration.
sudo-rs could be made to run programs as an administrator.
Software Description:
- rust-sudo-rs: Rust-based sudo and su implementations
It was discovered that sudo-rs incorrectly handled time-of-check vs time-
of-use conditions in sudoedit. A local attacker with permission to edit
specific files using sudoedit could use this issue to place files in
arbitrary directories, and possibly escalate their privileges. This issue
only affected systems configured to grant fine-grained sudoedit file
editing permissions, which is not the default configuration.
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS sudo-rs 0.2.13-0ubuntu1.2 In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8708-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
