Database/Kernel, userspace & hypervisor

sudo: Local privilege escalation via the `--host` option against host-specific sudoers rules
CVSS 7.0CVE-2025-32462Kernel, userspace & hypervisorcurated
Impact
Local privilege escalation via the --host option against host-specific sudoers rules
Who can reach it
Local user with any sudoers entry
What to do
Package update; no reboot
References
Related entries
- sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountCVE-2021-3156 · sudoHigh
- sudo: Local privilege escalation via the `--chroot` optionCVE-2025-32463 · sudoHigh
- glibc: Static setuid binaries incorrectly search LD_LIBRARY_PATH during dlopen - local privilege escalationCVE-2025-4802 · glibcHigh
- Xen (x86): CPU opcode cache corruption - host instability triggerable from a guestCVE-2025-54518 · Xen (x86)High
- libblockdev / udisks: allow_active to root via libblockdev through udisksCVE-2025-6019 · libblockdev / udisksHigh
- Linux kernel (arch/x86/kernel/fpu): A guest that disables an XSAVE feature through XFD while the saved XSTATE_BV stillCVE-2026-23005 · Linux kernel (arch/x86/kernel/fpu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.