Alerts This Week
Warning Icon 1 825
Alerts This Week
Warning Icon 1 825

Fedora 41: Advisory for sudo-rs CVE-2025-64170 Moderate Auth Bypass

fedora
Calendar Grey November 26, 2025
Dist Fedora Esm H88
Fixes critical issues in sudo-rs for Fedora 41, impacting authentication security with two notable CVEs.
Update to version 0.2.10

Summary

A memory safe implementation of sudo and su.

Update Information:

Update to version 0.2.10. This release includes fixes for CVE-2025-64170 and CVE-2025-64517.

Change Log

* Mon Nov 17 2025 Fabio Valentini - 0.2.10-1 - Update to version 0.2.10; Fixes RHBZ#2413768

References


[ 1 ] Bug #2414748 - CVE-2025-64170 sudo-rs: sudo-rs: Partial password reveal is possible after timeout [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2414748 [ 2 ] Bug #2414776 - CVE-2025-64517 sudo-rs: Authentication bypass in timestamp [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2414776

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ada7909175' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: sudo-rs
Product: Fedora 41
Version: 0.2.10
Release: 1.fc41
Summary: Memory safe implementation of sudo and su

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here