#1148890 sudo: CVE-2026-96512

Package:
src:sudo
Source:
src:sudo
Submitter:
Salvatore Bonaccorso
Date:
2026-09-28 13:07:02 UTC
Severity:
normal
Tags:
#1148890#5
Date:
2026-09-24 18:20:30 UTC
From:
To:
Hi,

The following vulnerability was published for sudo.

CVE-2026-96512[0]:
| A flaw was found in sudo. When sudoers rules use NOTBEFORE or
| NOTAFTER time-based access restrictions with timestamps that omit
| the trailing 'Z' timezone indicator, the time evaluation relies on
| the TZ environment variable inherited from the calling user. Because
| sudo is a setuid-root program, an unprivileged local user can set TZ
| to an extreme timezone offset to shift the authorization window by
| up to approximately 25 hours, causing expired rules to be treated as
| valid. This allows the user to execute commands outside the intended
| time window. Authentication is not bypassed; only the time-based
| authorization check is affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-96512
https://www.cve.org/CVERecord?id=CVE-2026-96512
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2539327
[2] https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148890#10
Date:
2026-09-25 19:04:52 UTC
From:
To:
Hi,

Some additional background on this issue in
https://www.openwall.com/lists/oss-security/2026/09/24/4 . There is a
first part of the fix by an another reporter, which is
https://github.com/sudo-project/sudo/commit/db669167ca599f2a94cd8a4c5fae9e473c81a2fd

So both commits are needed to address the TZ related issue.

Regards,
Salvatore

#1148890#13
Date:
2026-09-26 17:12:25 UTC
From:
To:
Hello,

Bug #1148890 in sudo reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/sudo-team/sudo/-/commit/b0ffc49625d1ed65d4e9331393d58ff0c605b59c
------------------------------------------------------------------------
Apply upstream patches to address CVE-2026-96512

Closes: #1148890
Thanks: Salvatore Bonaccorso

Also rediff existing patches

Add 0011-sudo-ignore-user-specified-TZ-environment-variable.patch: <REASON>
Add 0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch: <REASON>
Add 0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch: <REASON>
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148890

#1148890#18
Date:
2026-09-28 09:31:08 UTC
From:
To:
Hello,

Bug #1148890 in sudo reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/sudo-team/sudo/-/commit/ece12da82e9a4c78138b114226b25c35a1e20bff
------------------------------------------------------------------------
Apply upstream patches to address CVE-2026-96512

Closes: #1148890
Thanks: Salvatore Bonaccorso

Also rediff patches

Add 0008-Remove-TZ-from-sudo-s-working-environment-without-mo.patch: <REASON>
Add 0009-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch: <REASON>
Add 0007-sudo-ignore-user-specified-TZ-environment-variable.patch: <REASON>
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148890

#1148890#23
Date:
2026-09-28 13:05:21 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
sudo, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148890@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Marc Haber <mh+debian-packages@zugschlus.de> (supplier of updated sudo package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 14:40:42 +0200
Source: sudo
Architecture: source
Version: 1.9.17p2-9
Distribution: unstable
Urgency: medium
Maintainer: Debian Sudo Maintainers <sudo@packages.debian.org>
Changed-By: Marc Haber <mh+debian-packages@zugschlus.de>
Closes: 1148890
Changes:
 sudo (1.9.17p2-9) unstable; urgency=medium
 .
   * Apply upstream patches to address CVE-2026-96512.
     Thanks to Salvatore Bonaccorso (Closes: #1148890)
   * snapshot release
Checksums-Sha1:
 39e452ae4eece5750be486821e2d9f944ae94171 3027 sudo_1.9.17p2-9.dsc
 acd5fe445abc6d1ef6eb1d62c8dd6edd25f3470f 53368 sudo_1.9.17p2-9.debian.tar.xz
 5897c4a4a378507f2cffd0a3d74d2e72acb01d1a 8778164 sudo_1.9.17p2-9.git.tar.xz
 b917f840dc834cc5ce8fbde17c21bccfcf5b3e19 17724 sudo_1.9.17p2-9_source.buildinfo
Checksums-Sha256:
 00bb7906f77069443e6c6b7e341dc72de330ba3daf272836878ab8330a371c4a 3027 sudo_1.9.17p2-9.dsc
 d4d35d95bd3cf0c23fdd301ceef11ec2d51b710a013fab91a6a140e8d713bb1c 53368 sudo_1.9.17p2-9.debian.tar.xz
 55f116aa2194d812d11c56ad9c76206ad740f24f214f56c87e65b66dd2276df2 8778164 sudo_1.9.17p2-9.git.tar.xz
 121cba4199c6dea55e21e1f36c854d358e4145a123cded2ff76d67c24789c875 17724 sudo_1.9.17p2-9_source.buildinfo
Files:
 36c9f3708067a14ec05a37545b5282e9 3027 admin optional sudo_1.9.17p2-9.dsc
 a3e35f8c2776eb81a0f09e0004bda321 53368 admin optional sudo_1.9.17p2-9.debian.tar.xz
 fc1c49567b869978a8fd4553e799eefc 8778164 admin None sudo_1.9.17p2-9.git.tar.xz
 eac8127bb898a3bc92fbc128cb646541 17724 admin optional sudo_1.9.17p2-9_source.buildinfo
Git-Tag-Info: tag=a45d8ee126335ee114bf8e48f6e709ed719203b5 fp=6852d7634180aae6088c83ead54d300c376391c9
Git-Tag-Tagger: Marc Haber <mh+debian-packages@zugschlus.de>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmq6YV8ACgkQYG0ITkaD
wHn6Ow//T5wim22w5o4NSm0dUXKpESlF7HVP12EQ98XM/rmVS42MWxLGeSWMPG9f
Kmyq++JpcL9ic59bs1PMBxzSXnoXUPMzHKpN8WnBmYgff810lY3LU+MkcybU5cVd
3ujgTOzoukfk/UyAtFpy6FvrCUM4HMUka3iyDT5FGsX1/tZG7XWHydA1P3m9gl9c
T6VPHJ9Mfw8RreQxvta6vWh/ZYMWEWiQtU8pU7qSwWU9aIV1WdDJ5TcIrxtkJ03l
uMOPNW9CpZgEbuRtqKbTCCmPfyWWiRBZTgCq+pn/Qo1I6VqJw1D+9U/2uQ7tbrTd
lerpE7WQYrZ2cByLSRUGHA7sx7gHJq2SpIvbZ8RnXsYgz5oVMpcWteCjsWLzIs/x
ApjR+bO1x7ywUs0/6w4MYCgAf5m4DAk1ajOtf+VWvRgkMAe0OOybZpA9nTPdBBOr
h9EoDnwCpmt4EpvIIKFjqRWtKCXNudJZkGzQUKPmh2/T6B5AH7O7Wh8PKwLbW7js
zGWtMn5dSpG4dFWqMf1wVZPNfHA9vmiEwOG3z4mwjLcqxSao37CjRnQetY7DbJLu
F3WZBjgr/MoRJHp5kKldFU9H41ag6z0O49jo2m0IdEyhGuIpI3zvqTqQ8kRK+b9t
80Z7KyqdQ9wqJiQ4Zrc0Q7tNQ+NwzpqcI7pOq+prHOlyhA72Vzg=
=L+hB
-----END PGP SIGNATURE-----