Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libnss-sudo",
"binary_version": "1.9.15p5-3ubuntu5.24.04.3"
},
{
"binary_name": "sudo",
"binary_version": "1.9.15p5-3ubuntu5.24.04.3"
},
{
"binary_name": "sudo-ldap",
"binary_version": "1.9.15p5-3ubuntu5.24.04.3"
}
]
}