Database/Kernel, userspace & hypervisor

sudo: TZ from the calling user shifts NOTBEFORE/NOTAFTER windows, reviving expired rules
Impact
Where sudoers grants access only inside a time window, an unprivileged local user can move that window by up to roughly 25 hours by setting TZ before invoking sudo, because timestamps written without a trailing 'Z' are evaluated against the inherited timezone of a setuid-root process. Rules that were supposed to have expired are treated as still valid, so a command that was only meant to be runnable during a maintenance shift becomes runnable at will. On GPU fleets this matters wherever time-boxed sudo is used to hand operators, on-call staff or job wrappers temporary root-adjacent actions on nodes - resetting GPUs, reloading the driver, flashing firmware, draining a node. Authentication is still enforced; only the time check is bypassed, so the exposure is limited to principals who already appear in sudoers with a time restriction.
Who can reach it
Local user who already has a sudoers entry carrying a NOTBEFORE or NOTAFTER restriction with a non-'Z' timestamp. Requires a shell on the node and whatever authentication the sudoers rule demands; no remote path.
What to do
Install the vendor sudo update (Red Hat ships fixes via RHSA-2026:71609 and RHSA-2026:75580 for RHEL 7 through 10; the upstream fix is commit 1820a349687522f51023d1ae5925125f59679a8c). No reboot or daemon restart is needed - sudo is invoked per command, so the new binary takes effect immediately. As an interim mitigation, rewrite every NOTBEFORE/NOTAFTER timestamp in sudoers to the explicit UTC form with the trailing 'Z', which removes the TZ dependency without patching.
References
Related entries
- Linux slab allocator: ABA race in the optimistic freelist return corrupts the partial listCVE-2026-97941 · Linux kernel mm/slab (__slab_try_return_freelist ABA race)High
- Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain IDCVE-2026-98002 · Linux kernel iommu/amd (amd_iommu_alloc_domain_nested error check)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.