ELSA-2026-68692

ELSA-2026-68692 - sudo security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-09-17

Description


[1.9.17-6]
- Fix CVE-2026-82474: execveat(2) intercept/log_subcmds bypass

[1.9.17-5.p2]
- Resolves: RHEL-212546 - Use canonicalized path if user path contains '..'


Related CVEs


CVE-2026-82474

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_aarch64_appstream
sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_aarch64_baseos_latest
sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_aarch64_u2_baseos_patch
sudo-1.9.17-10.p2.el10_2.6.aarch64.rpm02970fcf9a46e68647a1345d09a059a7e546092c70267a0d95fdc95a43487133-ol10_aarch64_baseos_latest
sudo-1.9.17-10.p2.el10_2.6.aarch64.rpm02970fcf9a46e68647a1345d09a059a7e546092c70267a0d95fdc95a43487133-ol10_aarch64_u2_baseos_patch
sudo-python-plugin-1.9.17-10.p2.el10_2.6.aarch64.rpmd1c649f3537d283aa754780870ab327bdec2791be7ede900dae2c315ab95ecf6-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_x86_64_appstream
sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_x86_64_baseos_latest
sudo-1.9.17-10.p2.el10_2.6.src.rpm7b2db29be17a21c9a0a4818cbd6c57d19aafecd0131d5e69fc5b388169584466-ol10_x86_64_u2_baseos_patch
sudo-1.9.17-10.p2.el10_2.6.x86_64.rpmd734fa40d147bf1b2dafe2a159ce32f63ff006b6089d7dad55321aab30c94e6f-ol10_x86_64_baseos_latest
sudo-1.9.17-10.p2.el10_2.6.x86_64.rpmd734fa40d147bf1b2dafe2a159ce32f63ff006b6089d7dad55321aab30c94e6f-ol10_x86_64_u2_baseos_patch
sudo-python-plugin-1.9.17-10.p2.el10_2.6.x86_64.rpm2964b395d2a4ee2cac44d942152501fd425ad39f0f24778178cb65d094c74dbc-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete