CVE-2026-35535
EUVD-2026-1857103.04.2026, 03:16
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sudo_project | sudo | 𝑥 < 1.9.17 |
| sudo_project | sudo | 1.9.17 |
| sudo_project | sudo | 1.9.17:p1 |
| sudo_project | sudo | 1.9.17:p2 |
| siemens | sinec_os | 𝑥 < 4.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Siemens | RUGGEDCOM RST2428P | 𝑥 < V4.0 | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.9.15-10.p5.el10_1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.9.17-4.p2.el10_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.9.15-8.p5.el10_0.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | 0:1.8.6p3-29.el6_10.8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.8.23-10.el7_9.5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.9.5p2-1.el8_10.5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.9.5p2-1.el8_6.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:1.9.5p2-1.el8_6.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | 0:1.9.5p2-1.el8_6.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.9.5p2-1.el8_8.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.9.5p2-1.el8_8.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.9.17p2-3.el9_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.9.5p2-15.el9_7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:1.9.5p2-7.el9_0.6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.9.5p2-9.el9_2.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:1.9.5p2-10.el9_4.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.9.5p2-10.el9_6.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202605271418-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202605271328-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202606231112-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 415.92.202606030318-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202605200242-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202606250942-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202605260517-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202605201155-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1782353093 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1779798165 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1779798222 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| sudo |
| ||
| sudo-debuginfo |
| ||
| sudo-debugsource |
| ||
| sudo-devel |
| ||
| sudo-logsrvd |
| ||
| sudo-logsrvd-debuginfo |
| ||
| sudo-python-plugin |
| ||
| sudo-python-plugin-debuginfo |
|
Common Weakness Enumeration
- CWE-271 - Privilege Dropping / Lowering ErrorsThe software does not drop privileges before passing control of a resource to an actor that does not have those privileges.
- CWE-272 - Least Privilege ViolationThe elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
References