{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sudo--1.9.17p2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-82474"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sudo (\u003c= 1.9.17p2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Sudo"],"content_html":"\u003cp\u003eSudo versions up to and including 1.9.17p2 contain a security vulnerability (CVE-2026-82474) in the ptrace-based intercept mode. This feature, designed to enforce fine-grained policy restrictions on commands, fails to apply those policy checks to the \u003ccode\u003eexecveat\u003c/code\u003e system call. Consequently, a user who is granted sudo privileges for specific commands can bypass these restrictions to execute arbitrary programs that were intended to be blocked. The vulnerability is triggered by directly invoking \u003ccode\u003eexecveat\u003c/code\u003e or the \u003ccode\u003efexecve\u003c/code\u003e function. This flaw undermines the security integrity of sudo-restricted environments, as it allows attackers to execute denied programs while simultaneously bypassing audit logging mechanisms associated with policy enforcement. This vulnerability is highly relevant to organizations relying on sudo intercept mode for privilege limitation and command auditing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local users to escalate their privileges by executing unauthorized commands that would otherwise be blocked by sudo policies. This impacts security posture by enabling lateral movement, persistence, or unauthorized system changes within the context of the elevated sudo session. Given the widespread use of sudo across Linux-based infrastructure, the potential for unauthorized code execution in restricted environments is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Sudo package to version 1.9.17p3 or later to remediate CVE-2026-82474.\u003c/li\u003e\n\u003cli\u003eAudit existing sudoers configurations to identify environments where ptrace-based intercept mode is enabled.\u003c/li\u003e\n\u003cli\u003eMonitor system audit logs for anomalous \u003ccode\u003eexecveat\u003c/code\u003e system call activity originating from users with restricted sudo access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:41:22Z","date_published":"2026-08-29T17:41:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sudo-policy-bypass/","summary":"Sudo versions through 1.9.17p2 are vulnerable to a privilege escalation flaw where the ptrace-based intercept mode fails to filter execveat system calls, allowing unauthorized command execution.","title":"Sudo Policy Bypass via execveat System Call","url":"https://feed.craftedsignal.io/briefs/2026-08-sudo-policy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Sudo (\u003c= 1.9.17p2)","version":"https://jsonfeed.org/version/1.1"}