Skip to content
VulniPulse
Advisory severityHigh7.0Red Hat Linux

High [CVE-2025-32462] Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL

This high-severity Red Hat Linux advisory covers CVE-2025-32462 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.2 Advanced Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2025-32462 Source published Source updated

VulniPulse record published

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. A privilege escalation vulnerability was found in Sudo.

In certain configurations, unauthorized users can gain elevated system privileges via the Sudo host option (`-h` or `--host`). When using the default sudo security policy plugin (sudoers), the host option is intended to be used in conjunction with the list option (`-l` or `--list`) to determine what permissions a user has on a different system.

However, this restriction can be bypassed, allowing a user to elevate their privileges on one system to the privileges they may have on a different system, effectively ignoring the host identifier in any sudoers rules.

This vulnerability is particularly impactful for systems that share a single sudoers configuration file across multiple computers or use network-based user directories, such as LDAP, to provide sudoers rules on a system.

This vulnerability is classified as a Local Privilege Escalation (LPE), meaning an attacker needs an authenticated account before they could exploit it. Due to this restriction, the severity is rated Important.

Additionally, for a system to be vulnerable, it must already be in a non-default configuration.

Affected versions
  • < 1.9.17p1

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Fixed versions
  • sudo-0:1.9.15-8.p5.el10_0.2
  • sudo-0:1.8.23-10.el7_9.4
  • sudo-0:1.9.5p2-1.el8_10.1
  • sudo-0:1.8.29-5.el8_2.3
  • sudo-0:1.8.29-7.el8_4.3
  • sudo-0:1.9.5p2-1.el8_6.1
  • sudo-0:1.9.5p2-1.el8_8.1
  • sudo-0:1.9.5p2-10.el9_6.1
  • sudo-0:1.9.5p2-7.el9_0.5
  • sudo-0:1.9.5p2-9.el9_2.3
  • sudo-0:1.9.5p2-10.el9_4.1
  • rhcos-412.86.202507280202-0
  • rhcos-413.92.202509030117-0
  • rhcos-414.92.202508041909-0
  • rhcos-415.92.202507301737-0
  • rhcos-416.94.202507100308-0
  • rhcos-417.94.202507291008-0
  • rhcos-418.94.202507091512-0
  • rhcos-4.19.9.6.202507081759-0
  • RHSA-2025:11537
  • RHSA-2025:10871
  • RHSA-2025:10110
  • RHSA-2025:10518
  • RHSA-2025:10383
  • RHSA-2025:10520
  • RHSA-2025:10836
  • RHSA-2025:9978
  • RHSA-2025:10835
  • RHSA-2025:10779
  • RHSA-2025:10707
  • RHSA-2025:12323
  • RHSA-2025:15672
  • RHSA-2025:13289
  • RHSA-2025:12370
  • RHSA-2025:10781
  • RHSA-2025:12437
  • RHSA-2025:10767
  • RHSA-2025:10771

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.