THREAT BRIEF (HIGH): Critical Sudo Vulnerabilities Impact Major Linux Distributions
Security researchers have identified two newly disclosed vulnerabilities in Sudo, the widely used Linux and Unix utility that allows users to execute commands with elevated privileges.
These flaws could allow local attackers to gain root access, posing a serious risk across affected systems.
Sudo is essential for controlled privilege escalation in Unix-like environments. These new CVEs highlight a critical gap in versions widely deployed across enterprise and development infrastructure.
Key Vulnerabilities
- CVE-2025-32463 (CVSS 9.3 – Critical):
A vulnerability in Sudo’schrootfunctionality affects versions 1.9.14 to 1.9.17. Local users can exploit this flaw to gain full root access. Earlier versions are unaffected, as thechrootfeature wasn’t present. - CVE-2025-32462 (CVSS 2.8 – Low):
A privilege escalation issue in the Sudohostoption, impacting both stable (1.9.0–1.9.17) and legacy (1.8.8–1.8.32) versions. Though less severe, this vulnerability has existed for over a decade.
Affected systems include major Linux distributions like Ubuntu and Fedora, as well as macOS Sequoia, which shares the Unix-based architecture.
Fizen Technology Response
Our team is actively monitoring for indicators of compromise and applying vendor-recommended patches as they’re released. As always, we follow a layered defense strategy to minimize exposure and risk.
Recommended Action
There are no current workarounds for these vulnerabilities. Organizations should take the following steps immediately:
- Upgrade Sudo to version 1.9.17p1
- This release addresses both CVEs.
- Audit Sudo configurations
- Review the use of
HostandHost_Aliassettings in:
- Review the use of
/etc/sudoers/etc/sudoers.d/- LDAP-based policies (using
ldapsearchor equivalent tools)
Next Steps
- Ensure all systems using Sudo are patched without delay.
- Our team will continue to monitor developments.
Fizen Technology
Have questions? Contact us if you have technology questions for your business. We are here to help you with your IT needs, so you can focus on your business. We are grateful for PDI Security and Network Solutions for their assistance in gathering this brief information.

