CVE-2025-32462
CVE-2025-32462: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.0
High [CVE-2025-32462] Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL
CVE-2025-32462Source published Source updated
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. A privilege escalation vulnerability was found in Sudo. In certain configurations, unauthorized users can gain elevated system privileges via the Sudo host option (`-h` or `--host`). When using the default sudo security policy plugin (sudoers), the host option is intended to be used in conjunction with the list option (`-l` or `--list`) to determine what permissions a user has on a different system. However, this restriction can be bypassed, allowing a user to elevate their privileges on one system to the privileges they may have on a different system, effectively ignoring the host identifier in any sudoers…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Enterprise Linux 8.2 Advanced Update Support
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
18 more entries in the full advisory.
- Source-reported affected versions
- < 1.9.17p1
- Source-reported fixed versions
- sudo-0:1.9.15-8.p5.el10_0.2
- sudo-0:1.8.23-10.el7_9.4
- sudo-0:1.9.5p2-1.el8_10.1
- sudo-0:1.8.29-5.el8_2.3
34 more entries in the full advisory.
- Mitigation guidance
- For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.