Two new vulnerabilities in Sudo (a command-line utility for Linux and Unix-like operating systems) could allow local attackers to gain full root access, bypassing critical security checks. The findings were published by cybersecurity researchers at Stratascale and have raised alarm in the international Linux/Unix administrator community.

The vulnerabilities have been listed as:
- CVE-2025-32462 (CVSS score: 2.8): Affects versions of Sudo prior to 1.9.17p1. When used with a sudoers (which specifies a host that is neither the current host nor ALL), it allows listed users to execute commands on unintended hosts.
- CVE-2025-32463 (CVSS score: 9.3 – critical): Sudo before version 1.9.17p1 allows local users to gain root access because “/etc/nsswitch.conf” from a user-controlled directory is used with the –chroot option.
See also: Automation and vulnerability exploitation are boosting ransomware
Sudo is a command execution tool that allows users with low privileges to execute commands as another user, such as the superuser. By executing commands with sudo, the idea is to enforce the principle of least privilege. Users can perform administrative actions without the need for elevated privileges.
The vulnerabilities were discovered by Stratascale researcher Rich Mirch , who noted that the CVE-2025-32462 bug “had been hidden for over 12 years.” It relies on the “-h” (host) option to sudo, which allows a user to list sudo privileges for a different host. The feature was enabled in September 2013.
However, the bug made it possible to execute any command from the remote host on the local computer.
Sudo project maintainer Todd C. Miller confirmed the issue, saying: “This primarily affects websites that use a common sudoers file that is distributed across multiple machines. Websites that use LDAP-based sudoers (including SSSD) are similarly affected.”
See also: Grafana: Fixes vulnerabilities in Image Renderer plugin
The second vulnerability (CVE-2025-32463) is considered critical, as it allows the execution of arbitrary commands as root without requiring entry in sudoers, simply through proper handling of the “-R” (chroot) option.

"The default configuration of Sudo is vulnerable," Mirch said. "Although the vulnerability includes the Sudo chroot feature, it does not require the user to define Sudo rules. As a result, any local user without privileges could potentially escalate privileges to root if a vulnerable version is installed."
In other words, the vulnerability allows an attacker to trick sudo into loading an arbitrary shared library (creating a “/etc/nsswitch.conf” configuration file under the user-specified root directory) and potentially execute malicious commands with elevated privileges.
Miller said the chroot option will be removed completely from a future version of Sudo.
Recommendations for system administrators
- Upgrade immediately to Sudo version 1.9.17p1 or later.
- Check the configuration of the
sudoers, especially in shared environments or LDAP/SSSD integration. - Limit the use of
--chrootand confirm that critical files cannot be retrieved from untrusted locations. - Implement user isolation and continuous monitoring practices for early detection of abuse.
See also: Chinese hackers target France via Ivanti zero-day vulnerabilities
The incident once again highlights the importance of regularly auditing even the most fundamental tools in the Linux ecosystem. Sudo, while designed for security and flexibility, is not immune to flaws. Timely updates and proper access policy management remain the best defenses against both localized and targeted attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Many major Linux distributions issued security warnings and updates:
- CVE-2025-32462: AlmaLinux 8 & 9, Alpine Linux, Amazon Linux, Debian, Gentoo , Oracle Linux, Red Hat, SUSE, Ubuntu
- CVE-2025-32463: Alpine Linux, Amazon Linux, Debian, Gentoo, Red Hat, SUSE, Ubuntu
Source: thehackernews.com
