Database/Kernel, userspace & hypervisor

sudo: Local privilege escalation via the `--chroot` option
CVSS 7.8CVE-2025-32463Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Local privilege escalation via the --chroot option - any local user reaches root on default sudoers, no sudo rights needed [KEV]
Who can reach it
Local user, incl. inside a container that ships sudo
What to do
Package update (sudo >= 1.9.17p1); no reboot. Also rebuild every container base image that includes sudo - the host fix does not cover tenant images
References
Related entries
- sudo: Local privilege escalation via the `--host` option against host-specific sudoers rulesCVE-2025-32462 · sudoHigh
- sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountCVE-2021-3156 · sudoHigh
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketCVE-2025-37756 · Linux kernel (net/tls)High
- Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with aCVE-2025-37761 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/nouveau): A buffer object imported over PRIME leaves a dangling pointer behind, and theCVE-2025-37765 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverCVE-2025-37854 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.