CVE-2025-32462

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-32462
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32462.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-32462
Downstream
Related
Published
2025-06-30T21:15:30Z
Modified
2025-07-29T11:22:02.295941Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

References

Affected packages

Debian:11 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.5p2-3+deb11u2

Affected versions

1.*

1.9.5p2-3
1.9.5p2-3+deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.13p3-1+deb12u2

Affected versions

1.*

1.9.13p3-1
1.9.13p3-1+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.16p2-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/sudo-project/sudo

Affected ranges

Type
GIT
Repo
https://github.com/sudo-project/sudo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

SUDO_1_3_0
SUDO_1_3_1
SUDO_1_4_0
SUDO_1_5_0
SUDO_1_5_1
SUDO_1_5_2
SUDO_1_5_3
SUDO_1_5_4
SUDO_1_5_6
SUDO_1_5_7
SUDO_1_5_8
SUDO_1_5_9
SUDO_1_6_0
SUDO_1_6_1
SUDO_1_6_2
SUDO_1_6_3
SUDO_1_6_4
SUDO_1_6_5
SUDO_1_6_6
SUDO_1_6_7
SUDO_1_6_8
SUDO_1_6_8p1
SUDO_1_7_0
SUDO_1_7_1
SUDO_1_7_2
SUDO_1_8_0
SUDO_1_9_0
SUDO_1_9_1
SUDO_1_9_10
SUDO_1_9_11
SUDO_1_9_11p1
SUDO_1_9_11p2
SUDO_1_9_11p3
SUDO_1_9_12
SUDO_1_9_12p1
SUDO_1_9_12p2
SUDO_1_9_13
SUDO_1_9_13p1
SUDO_1_9_13p2
SUDO_1_9_13p3
SUDO_1_9_14
SUDO_1_9_14p1
SUDO_1_9_14p2
SUDO_1_9_14p3
SUDO_1_9_15
SUDO_1_9_15p1
SUDO_1_9_15p2
SUDO_1_9_15p3
SUDO_1_9_15p4
SUDO_1_9_15p5
SUDO_1_9_16
SUDO_1_9_16p1
SUDO_1_9_16p2
SUDO_1_9_2
SUDO_1_9_3
SUDO_1_9_3p1
SUDO_1_9_4
SUDO_1_9_4p1
SUDO_1_9_4p2
SUDO_1_9_5
SUDO_1_9_5p1
SUDO_1_9_5p2
SUDO_1_9_6
SUDO_1_9_6p1
SUDO_1_9_7
SUDO_1_9_7p1
SUDO_1_9_7p2
SUDO_1_9_8
SUDO_1_9_8p1
SUDO_1_9_8p2
SUDO_1_9_9
TAG

v1.*

v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.6
v1.5.7
v1.5.8
v1.5.9
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.6.7
v1.6.8
v1.6.8p1
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.11p1
v1.9.11p2
v1.9.11p3
v1.9.12
v1.9.12p1
v1.9.12p2
v1.9.13
v1.9.13p1
v1.9.13p2
v1.9.13p3
v1.9.14
v1.9.14p1
v1.9.14p2
v1.9.14p3
v1.9.15
v1.9.15p1
v1.9.15p2
v1.9.15p3
v1.9.15p4
v1.9.15p5
v1.9.16
v1.9.16p1
v1.9.16p2
v1.9.2
v1.9.3
v1.9.3p1
v1.9.4
v1.9.4p1
v1.9.4p2
v1.9.5
v1.9.5p1
v1.9.5p2
v1.9.6
v1.9.6p1
v1.9.7
v1.9.7p1
v1.9.7p2
v1.9.8
v1.9.8p1
v1.9.8p2
v1.9.9