Critical Sudo Vulnerability in Ubuntu Allows Privilege Escalation

Critical Sudo Vulnerability in Ubuntu Allows Privilege Escalation

First seen 13 Mar 2026, 03:13 UTC UbuntuLinuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Sudo command has been identified, affecting Ubuntu versions 25.10, 24.04 LTS, and 22.04 LTS. The flaw arises from Sudo's improper handling of return codes when dropping privileges to execute the mailer, potentially allowing local attackers to escalate their privileges. This vulnerability does not have a CVE identifier mentioned in the articles. Users are advised to update their systems to specific package versions to mitigate the risk. The affected package versions include Sudo 1.9.17p2-1ubuntu1.1 for Ubuntu 25.10, Sudo 1.9.15p5-3ubuntu5.24.04.2 for Ubuntu 24.04 LTS, and Sudo 1.9.9-1ubuntu2.6 for Ubuntu 22.04 LTS. A standard system update will apply the necessary changes. The vulnerability poses a significant risk to systems running these versions, making immediate action necessary.

Key Points: • Critical vulnerability in Sudo allows local privilege escalation on affected Ubuntu versions. • Affected versions include Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. • Users should update to specific package versions to mitigate the risk.

Timeline

2026-03-12
Ubuntu releases advisory USN-8092 regarding Sudo vulnerability.
2026-03-12
Linuxsecurity publishes article on the Sudo vulnerability.