CLSA-2026-1778073563

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1778073563.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1778073563
Upstream
  • CVE-2026-35535
Published
2026-05-06T14:38:51Z
Modified
2026-06-01T00:30:10.794092225Z
Summary
sudo: Fix of CVE-2026-35535
Details
  • CVE-2026-35535: drop group privileges and supplementary groups before running the mailer in execmailer(), make setuid/setgid/setgroups failures fatal, and pass user gid alongside uid when NOROOT_MAILER is defined
References

Affected packages

TuxCare:AlmaLinux:9.6 / sudo

Package

Name
sudo
Purl
pkg:rpm/tuxcare/sudo?distro=almalinux-9.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.5p2-10.el9_6.2.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1778073563.json"

TuxCare:AlmaLinux:9.6 / sudo-devel

Package

Name
sudo-devel
Purl
pkg:rpm/tuxcare/sudo-devel?distro=almalinux-9.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.5p2-10.el9_6.2.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1778073563.json"

TuxCare:AlmaLinux:9.6 / sudo-python-plugin

Package

Name
sudo-python-plugin
Purl
pkg:rpm/tuxcare/sudo-python-plugin?distro=almalinux-9.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.5p2-10.el9_6.2.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1778073563.json"