Hi, The following vulnerability was published for sudo. CVE-2026-82474[0]: | Sudo through 1.9.17p2 fails to apply intercept policy checks to the | execveat system call in ptrace-based intercept mode. Users permitted | to run specific commands can execute denied programs by calling | execveat directly or through fexecve, bypassing policy enforcement | and logging. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-82474 https://www.cve.org/CVERecord?id=CVE-2026-82474 [1] https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Control: tags -1 security upstream wontfix thanks We talked about this offline and decided neither to do a DSA nor to pull the upstream fix for forky. Tagging this wontfix, will close it with the next upstream release. Greetings Marc
Control: tags -1 security upstream wontfix thanks We talked about this offline and decided neither to do a DSA nor to pull the upstream fix for forky. Tagging this wontfix, will close it with the next upstream release. Greetings Marc
Hi Marc, I have marked the issue as unimportant in the security-tracker and once a new upstream version includes the fix and this bug is closed we will simply update the unstable version tracking along. Regards, Salvatore