Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Security update. Publication date: 15 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0211.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-35535 Description: In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. (CVE-2026-35535) References: - https://bugs.mageia.org/show_bug.cgi?id=35434 - https://lists.fedoraproject.org/archives/list/
Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1
Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1
Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e5d5fc359d 2026-06-04 01:48:27.004460+00:00 -------------------------------------------------------------------------------- Name : pie Product : Fedora 44 Version : 1.4.5 Release : 1.fc44 URL : https://github.com/php/pie Summary : PHP Installer for Extensions Description : PIE (PHP Installer for Extensions). PIE can install an extension to any installed PHP version. A list of extensions that support PIE can be found on https://packagist.org/extensions. Documentation: /usr/share/doc/pie/docs/usage.md -------------------------------------------------------------------------------- Update Information: Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self- update verify and write GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap) GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal) GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2026 Remi Collet - 1.4.5-1 - update to1.4.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e5d5fc359d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b2fe14ec86 2026-06-04 01:35:07.681084+00:00 -------------------------------------------------------------------------------- Name : pie Product : Fedora 43 Version : 1.4.5 Release : 1.fc43 URL : https://github.com/php/pie Summary : PHP Installer for Extensions Description : PIE (PHP Installer for Extensions). PIE can install an extension to any installed PHP version. A list of extensions that support PIE can be found on https://packagist.org/extensions. Documentation: /usr/share/doc/pie/docs/usage.md -------------------------------------------------------------------------------- Update Information: Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self- update verify and write GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap) GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal) GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2026 Remi Collet - 1.4.5-1 - update to1.4.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b2fe14ec86' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: sudo security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:12310", "synopsis": "Important: sudo security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for sudo.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.\n\nSecurity Fix(es):\n\n* sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2454714", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454714", "description": ""}], "cves": [{"name": "CVE-2026-35535", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35535", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.4", "cwe": "CWE-272"}], "references": [], "publishedAt": "2026-05-03T12:03:41.515195Z", "rpms": {"Rocky Linux 9": {"nvras": ["sudo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-0:1.9.5p2-15.el9_7.src.rpm", "sudo-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.ppc64le.rpm","sudo-debugsource-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay safe with this important sudo security update for Rocky Linux. Learn about critical privilege escalation fixing details here.. Rocky Linux sudo security upgrade CVE-2026-35535 privilege escalation. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-12310 http://linux.oracle.com/errata/ELSA-2026-12310.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: sudo-1.9.5p2-15.el9_7.x86_64.rpm sudo-python-plugin-1.9.5p2-15.el9_7.x86_64.rpm aarch64: sudo-1.9.5p2-15.el9_7.aarch64.rpm sudo-python-plugin-1.9.5p2-15.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/sudo-1.9.5p2-15.el9_7.src.rpm Related CVEs: CVE-2026-35535 Description of changes: [1.9.5p2-15] RHEL 9.7.0 ERRATUM - CVE-2026-35535 - Privilege escalation due to failure in privilege drop calls Resolves: RHEL-166065 _______________________________________________ El-errata mailing list
Important: sudo security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11521", "synopsis": "Important: sudo security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for sudo.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.\n\nSecurity Fix(es):\n\n* sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2454714", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454714", "description": ""}], "cves": [{"name": "CVE-2026-35535", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35535", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.4", "cwe": "CWE-272"}], "references": [], "publishedAt": "2026-04-30T18:00:45.302131Z", "rpms": {"Rocky Linux 8": {"nvras": ["sudo-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-0:1.9.5p2-1.el8_10.5.src.rpm", "sudo-0:1.9.5p2-1.el8_10.5.x86_64.rpm", "sudo-debuginfo-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-debuginfo-0:1.9.5p2-1.el8_10.5.x86_64.rpm", "sudo-debugsource-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-debugsource-0:1.9.5p2-1.el8_10.5.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important sudo security update available for Rocky Linux 8 to address privilege escalation risk.. Rocky Linux Sudo Update ImportantPrivilege Escalation. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.