Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42 sudo-rs Important Auth Bypass CVE-2025-64517 2025-4388808bbf

fedora
Calendar Grey November 26, 2025
Dist Fedora Esm H88
Fedora 42's sudo-rs update addresses critical fixes for authentication bypass vulnerabilities and more.
Update to version 0.2.10

Summary

A memory safe implementation of sudo and su.

Update Information:

Update to version 0.2.10. This release includes fixes for CVE-2025-64170 and CVE-2025-64517.

Change Log

* Mon Nov 17 2025 Fabio Valentini - 0.2.10-1 - Update to version 0.2.10; Fixes RHBZ#2413768

References


[ 1 ] Bug #2414749 - CVE-2025-64170 sudo-rs: sudo-rs: Partial password reveal is possible after timeout [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2414749 [ 2 ] Bug #2414777 - CVE-2025-64517 sudo-rs: Authentication bypass in timestamp [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2414777

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4388808bbf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: sudo-rs
Product: Fedora 42
Version: 0.2.10
Release: 1.fc42
Summary: Memory safe implementation of sudo and su

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here