Description
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 03 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. | |
| Weaknesses | CWE-271 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T02:21:33.584Z
Reserved: 2026-04-03T02:21:32.829Z
Link: CVE-2026-35535
No data.
Status : Received
Published: 2026-04-03T03:16:18.233
Modified: 2026-04-03T03:16:18.233
Link: CVE-2026-35535
No data.
OpenCVE Enrichment
No data.
Weaknesses