ELSA-2026-75579

ELSA-2026-75579 - sudo security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-10-06

Description


[1.9.17-7]
- CVE-2026-96512 sudo: sudo: TZ environment variable allows bypass of
NOTBEFORE/NOTAFTER time-based authorization [rhel-10.2.z]

[1.9.17-6]
- Fix CVE-2026-82474: execveat(2) intercept/log_subcmds bypass

[1.9.17-5.p2]
- Resolves: RHEL-212546 - Use canonicalized path if user path contains '..'

[1.9.17-4.p2]
- Bump release number
- Resolves: RHEL-164620 - CVE-2026-35535 sudo: Sudo: Privilege escalation
due to failure in privilege drop calls

[1.9.17-3.p2]
- Resolves: RHEL-164620 - CVE-2026-35535 sudo: Sudo: Privilege escalation
due to failure in privilege drop calls

[1.9.17-2.p2]
- Resolves: RHEL-59136 - sudo passes SHELL environment variable twice to
the shell being executed [rhel-10]
- Resolves: RHEL-128212 - [RFE] request to backport support for regex in
sudo [rhel-10]
- Resolves: RHEL-112100 - Rebase of sudo to 1.9.17p2 [rhel-10]

[1.9.17-1.p2]
- Rebase sudo to 1.9.17p2
- Resolves: RHEL-122752

[1.9.15-9.p5]
- RHEL 10.1 ERRATUM
- CVE-2025-32462 sudo: LPE via host option Resolves: RHEL-100009
- CVE-2025-32463 sudo: LPE via chroot option Resolves: RHEL-100022

[1.9.15-8.p5]
- Bump release for October 2024 mass rebuild:

[1.9.15-7.p5]
- RHEL 10.0 ERRATUM
- sudo-1.9.15-2.p5.el10: RHEL SAST Automation: address 4 High impact true
positive(s) Resolves: RHEL-44436
- sudo subpackage sudo-logsrvd should not be built Resolves: RHEL-52864


Related CVEs


CVE-2026-96512

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_aarch64_appstream
sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_aarch64_baseos_latest
sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_aarch64_u2_baseos_patch
sudo-1.9.17-10.p2.el10_2.7.aarch64.rpmbc3a92ecbe0d8ef5eaab251a07f9bf9caf2f5f9141d1a5be7d39f4a642bcdf1c-ol10_aarch64_baseos_latest
sudo-1.9.17-10.p2.el10_2.7.aarch64.rpmbc3a92ecbe0d8ef5eaab251a07f9bf9caf2f5f9141d1a5be7d39f4a642bcdf1c-ol10_aarch64_u2_baseos_patch
sudo-python-plugin-1.9.17-10.p2.el10_2.7.aarch64.rpmadd2c4f3817acbe2e0bb97b753f4ad37484d160ac379653f2ba36f0631cfe54a-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_x86_64_appstream
sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_x86_64_baseos_latest
sudo-1.9.17-10.p2.el10_2.7.src.rpm17611ac143d10faf8881842639edaf87a987ff6753c236c8824d2edb466b1ac4-ol10_x86_64_u2_baseos_patch
sudo-1.9.17-10.p2.el10_2.7.x86_64.rpmea23c01903d04390315ce985d510d629a34b455e0936a97b1a04d8c84ca5f52a-ol10_x86_64_baseos_latest
sudo-1.9.17-10.p2.el10_2.7.x86_64.rpmea23c01903d04390315ce985d510d629a34b455e0936a97b1a04d8c84ca5f52a-ol10_x86_64_u2_baseos_patch
sudo-python-plugin-1.9.17-10.p2.el10_2.7.x86_64.rpm42e7c70494ea6d64e52539446984723022e2e699a6b133692b261ee66ac50417-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete