Skip to content

CVE-2026-35535 on CTRL-OS 26.05

Aliases: CVE-2026-35535

Packages: sudo

Status: Plausible

Advisory Information

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Updates

2026-07-09 21:53 CEST

Metadata changes:

  • Status for package sudo: “Plausible

(Amended on: 2026-07-13 20:20 CEST)

2026-07-09 21:53 CEST

Metadata changes:

  • Status for package sudo: “New

(Amended on: 2026-07-13 20:20 CEST)