CVE-2025-32463

unknown KEV
Published 2025-09-29 ยท Modified 2025-09-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.5

Description

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudoโ€™s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

CISA KEV

Vendor
Sudo
Product
Sudo
Due date
2025-10-20

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-52352 local linux
Stratascale ยท 2025-07-08

Sudo chroot 1.9.17 - Local Privilege Escalation

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

Sudo Chroot 1.9.17 Privilege Escalation
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.9.16p2-3
sid Fixed 1.9.16p2-3
forky Fixed 1.9.16p2-3
bullseye Fixed 0
bookworm Fixed 0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.