selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade sudo | May 4, 2022 | Jan 12, 2021 |
| Alpine Linux | — | Upgrade sudo | Aug 22, 2024 | Jan 12, 2021 |
| Centos_linux | — | Upgrade sudo-debugsourceUpgrade sudo-debuginfoUpgrade sudo | Jun 1, 2021 | Jan 12, 2021 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Jan 12, 2021 |
| Gentoo Linux | — | Upgrade app-admin/sudo. | Jan 27, 2021 | Jan 12, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade sudo | Apr 30, 2021 | Jan 12, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sudo | Mar 24, 2021 | Jan 12, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade sudo | Feb 2, 2021 | Jan 12, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade sudo | Feb 8, 2021 | Jan 12, 2021 |
| Oracle_linux | — | Upgrade sudo | May 26, 2021 | Jan 11, 2021 |
| Redhat_linux | — | No solution existsUpgrade sudoUpgrade sudo-debuginfoUpgrade sudo-debugsource | May 21, 2021 | Jan 12, 2021 |
| Rocky_linux | rocky-upgrade-sudorocky-upgrade-sudo-debuginforocky-upgrade-sudo-debugsource | Mar 12, 2024 | Jan 12, 2021 | |
| Suse | — | suse-upgrade-sudosuse-upgrade-sudo-develsuse-upgrade-sudo-plugin-pythonsuse-upgrade-sudo-test | Jan 28, 2021 | Jan 12, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 12, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub