top of page
perceptive_background_267k.jpg

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific command…

Published:

29 August 2026 at 00:00:00

Alert date:

29 August 2026 at 20:03:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-82474 affects Sudo through version 1.9.17p2, where ptrace-based intercept mode fails to apply policy checks to the execveat system call. This allows users who are permitted to run specific commands to execute otherwise denied programs by calling execveat directly or via fexecve. The bypass circumvents both policy enforcement and logging mechanisms, representing a significant privilege escalation risk. The vulnerability exists in the exec_ptrace.c source file of the sudo-project. A patch has been committed to the official sudo repository to address this flaw. Organizations relying on Sudo's intercept mode for command restrictions are directly impacted. The issue highlights a gap in system call coverage within sudo's security enforcement layer.

Technical details

Mitigation steps:

Affected products:

Sudo 1.9.17p2 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page