ELBA-2025-6577

ELBA-2025-6577 - sudo bug fix and enhancement update

Type:BUG
Impact:NA
Release Date:2025-06-09

Description


[1.9.15-8.p5]
- Bump release for October 2024 mass rebuild:

[1.9.15-7.p5]
- RHEL 10.0 ERRATUM
- sudo-1.9.15-2.p5.el10: RHEL SAST Automation: address 4 High impact true
positive(s) Resolves: RHEL-44436
- sudo subpackage sudo-logsrvd should not be built Resolves: RHEL-52864

[1.9.15-6.p5]
- RHEL 10.0 ERRATUM
- sudo-1.9.15-2.p5.el10: RHEL SAST Automation: address 4 High impact true
positive(s) Resolves: RHEL-44436
- sudo subpackage sudo-logsrvd should not be built Resolves: RHEL-52864

[1.9.15-5.p5]
- RHEL 10.0 ERRATUM
- sudo-1.9.15-2.p5.el10: RHEL SAST Automation: address 4 High impact true
positive(s) Resolves: RHEL-44436
- sudo subpackage sudo-logsrvd should not be built Resolves: RHEL-52864

[1.9.15-4.p5]
- Bump release for June 2024 mass rebuild

[1.9.15-3.p5]
- Enable RHEL gating for sudo

[1.9.15-2.p5]
- Avoid sendmail build dependency

[1.9.15-1.p5]
- Rabase to 1.9.15p5
- sudo-1_9_15p5 is available Resolves: rhbz#2248505
- TRIAGE CVE-2023-42465 sudo: Targeted Corruption of Register and Stack
Variables Resolves: rhbz#2255569

[1.9.14-1.p3]
- Rebase to 1.9.14p3
- sudo-1_9_14p2 is available Resolves: rhbz#2175672
- sudo fails to build with Python 3.12: FAILED: testcase
check_example_group_plugin_is_able_to_debug() Resolves: rhbz#2186412

[1.9.13-6.p2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

[1.9.13-5.p2]
- Rebuilt for Python 3.12

[1.9.13-4.p2]
- migrated to SPDX license

[1.9.13-3.p2]
- Rebuilt for Python 3.12

[1.9.13-2.p2]
- Port configure script to C99

[1.9.13-1.p2]
- Rebase to sudo 1.9.13p2
- sudo-1.9.13p2 is available Resolves: rhbz#2169840
- sudo: double free with per-command chroot sudoers rules Resolves:
CVE-2023-27320

[1.9.12-1.p2]
- Rebase to sudo 1.9.12p2
- sudo-1.9.12p2 is available Resolves: rhbz#2137775
- sudo: arbitrary file write with privileges of the RunAs user Resolves:
CVE-2023-22809




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete