Critical Privilege Escalation Vulnerability in sudo-rs Affects Ubuntu Systems

Critical Privilege Escalation Vulnerability in sudo-rs Affects Ubuntu Systems

First seen 1 Sep 2026, 22:29 UTC UbuntuLinuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

A vulnerability was discovered in sudo-rs that improperly handled time-of-check vs time-of-use conditions in sudoedit. This flaw allows local attackers with specific file editing permissions to place files in arbitrary directories, potentially escalating their privileges. The issue affects systems configured for fine-grained sudoedit permissions, which is not the default setup. Users are advised to update their systems to mitigate this risk. The vulnerability is documented under USN-8708-1. A standard system update will address the issue across affected systems. Ubuntu Pro offers extended security coverage for users needing additional support.

Key Points: • sudo-rs vulnerability allows privilege escalation via sudoedit. • Affected systems require specific fine-grained sudoedit permissions. • Immediate system updates are recommended to mitigate risks.

Timeline

2026-09-01
Vulnerability disclosed in sudo-rs
A flaw in sudoedit was found, allowing privilege escalation for local attackers with specific permissions.
Ubuntu
2026-09-01
Patch released for sudo-rs
Ubuntu released updates to address the sudo-rs vulnerability, urging users to apply them promptly.
Linuxsecurity