GPU VulnDB

Database/Kernel, userspace & hypervisor

sudo: TZ from the calling user shifts NOTBEFORE/NOTAFTER windows, reviving expired rules

CVSS 7.8CVE-2026-96512Kernel, userspace & hypervisorcurated

Impact

Where sudoers grants access only inside a time window, an unprivileged local user can move that window by up to roughly 25 hours by setting TZ before invoking sudo, because timestamps written without a trailing 'Z' are evaluated against the inherited timezone of a setuid-root process. Rules that were supposed to have expired are treated as still valid, so a command that was only meant to be runnable during a maintenance shift becomes runnable at will. On GPU fleets this matters wherever time-boxed sudo is used to hand operators, on-call staff or job wrappers temporary root-adjacent actions on nodes - resetting GPUs, reloading the driver, flashing firmware, draining a node. Authentication is still enforced; only the time check is bypassed, so the exposure is limited to principals who already appear in sudoers with a time restriction.

Who can reach it

Local user who already has a sudoers entry carrying a NOTBEFORE or NOTAFTER restriction with a non-'Z' timestamp. Requires a shell on the node and whatever authentication the sudoers rule demands; no remote path.

What to do

Install the vendor sudo update (Red Hat ships fixes via RHSA-2026:71609 and RHSA-2026:75580 for RHEL 7 through 10; the upstream fix is commit 1820a349687522f51023d1ae5925125f59679a8c). No reboot or daemon restart is needed - sudo is invoked per command, so the new binary takes effect immediately. As an interim mitigation, rewrite every NOTBEFORE/NOTAFTER timestamp in sudoers to the explicit UTC form with the trailing 'Z', which removes the TZ dependency without patching.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.