Update to version 0.2.10. This release includes fixes for CVE-2025-64170 and CVE-2025-64517.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a9d9780cbb 2025-11-26 00:50:04.944073+00:00 -------------------------------------------------------------------------------- Name : sudo-rs Product : Fedora 43 Version : 0.2.10 Release : 1.fc43 URL : https://github.com/trifectatechfoundation/sudo-rs Summary : Memory safe implementation of sudo and su Description : A memory safe implementation of sudo and su. -------------------------------------------------------------------------------- Update Information: Update to version 0.2.10. This release includes fixes for CVE-2025-64170 and CVE-2025-64517. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 17 2025 Fabio Valentini - 0.2.10-1 - Update to version 0.2.10; Fixes RHBZ#2413768 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2414750 - CVE-2025-64170 sudo-rs: sudo-rs: Partial password reveal is possible after timeout [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414750 [ 2 ] Bug #2414778 - CVE-2025-64517 sudo-rs: Authentication bypass in timestamp [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414778 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a9d9780cbb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.