CVE-2025-32462

Updated: 2025-07-06 01:30:18.329221

Description:

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0
CVSS Version 3.x HIGH 7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU sudo 1.9.5p2 7.0 HIGH Needs Triage 2025-07-01 12:53:28
CentOS 6 ELS sudo 1.8.6p3 7.0 HIGH Not Vulnerable 2025-07-08 00:19:20 Not vulnerable
CentOS 7 ELS sudo 1.8.23 7.0 HIGH In Rollout CLSA-2025:1751900234 2025-07-08 00:19:20
CentOS 8.4 ELS sudo 1.8.29-7 7.0 HIGH Released CLSA-2025:1751913478 2025-07-08 00:19:18
CentOS 8.5 ELS sudo 1.8.29-7 7.0 HIGH Released CLSA-2025:1751913630 2025-07-08 00:19:19
CentOS Stream 8 ELS sudo 1.9.5p2 7.0 HIGH Released CLSA-2025:1751913242 2025-07-08 04:29:12
CloudLinux 6 ELS sudo 1.8.6p3 7.0 HIGH Not Vulnerable 2025-07-08 00:19:20 Not vulnerable
CloudLinux 7 ELS sudo 1.8.23 7.0 HIGH In Rollout CLSA-2025:1751900044 2025-07-09 01:18:33
Oracle Linux 6 ELS sudo 1.8.6p3 7.0 HIGH Not Vulnerable 2025-07-08 00:19:21 Not vulnerable
Oracle Linux 7 ELS sudo 1.8.23 7.0 HIGH Released CLSA-2025:1751893905 2025-07-08 04:29:11
Total: 14