8.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Sudo through 1.9.17p2 Intercept Policy Bypass via execveat
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
References
-
Patch Commit patch
-
https://github.com/sudo-project/sudo/blob/v1.9.17p2/src/exec_ptrace.c technical-description
-
VulnCheck Advisory: Sudo through 1.9.17p2 Intercept Policy Bypass via execveat third-party-advisory
Affected products
- =<1.9.17p2
Matching in nixpkgs
pkgs.sudo
Command to run commands as root
pkgs.qsudo
Graphical sudo utility from Project Trident
-
nixos-unstable 2020.03.27
- nixpkgs-unstable 2020.03.27
- nixos-unstable-small 2020.03.27
-
nixos-26.05 2020.03.27
- nixos-26.05-small 2020.03.27
- nixpkgs-26.05-darwin 2020.03.27
pkgs.sudo-rs
Memory safe implementation of sudo and su
pkgs.psudohash
Password list generator for orchestrating brute force attacks and cracking hashes
pkgs.sudo-font
Font for programmers and command line users
pkgs.gnome-sudoku
Test your logic skills in this number grid puzzle
pkgs.doas-sudo-shim
Shim for the sudo command that utilizes doas
pkgs.lxqt.lxqt-sudo
GUI frontend for sudo/su
pkgs.run0-sudo-shim
Shim for the sudo command that utilizes run0
pkgs.yaziPlugins.sudo
Call `sudo` in yazi
-
nixos-unstable 0-unstable-2026-05-07
- nixpkgs-unstable 0-unstable-2026-05-07
- nixos-unstable-small 0-unstable-2026-08-26
-
nixos-26.05 0-unstable-2026-05-07
- nixos-26.05-small 0-unstable-2026-05-07
- nixpkgs-26.05-darwin 0-unstable-2026-05-07
pkgs.kdePackages.ksudoku
KSudoku is a logic-based symbol placement puzzle
pkgs.fishPlugins.plugin-sudope
Fish plugin to quickly put 'sudo' in your command
-
nixos-unstable 0-unstable-2025-09-16
- nixpkgs-unstable 0-unstable-2025-09-16
- nixos-unstable-small 0-unstable-2025-09-16
-
nixos-26.05 0-unstable-2025-09-16
- nixos-26.05-small 0-unstable-2025-09-16
- nixpkgs-26.05-darwin 0-unstable-2025-09-16
Package maintainers
-
@dani0854 Danil Suetin <suetin085+nixpkgs@protonmail.com>
-
@Anomalocaridid Duncan Russell <duncan@anomalocaris.xyz>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@nekowinston winston <hey@winston.sh>
-
@theCapypara Marco Köpcke <hello@capypara.de>
-
@thunze Tom Hunze
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@K900 Ilya K. <me@0upti.me>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@romildo José Romildo Malaquias <malaquias@gmail.com>
-
@exploitoverload Asier Armenteros <nix@exploitoverload.com>
-
@zimward zimward <zimward@zimward.moe>
-
@kuflierl Kennet Flierl <kuflierl@gmail.com>
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@rhendric Ryan Hendrickson
-
@pancaek paneku
-
@R-VdP Ramses <ramses@well-founded.dev>
-
@nicoonoclaste nicoo <nicoo@debian.org>
-
@adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
-
@khaneliman Austin Horstman <khaneliman12@gmail.com>