Two vulnerabilities in Sudo—CVE-2025-32462 and CVE-2025-32463—were disclosed as affecting a wide range of Unix and Unix-like platforms, including RHEL, CentOS, AlmaLinux, openSUSE, Ubuntu, Fedora, Debian, Arch Linux, FreeBSD, NetBSD, Oracle Linux, and macOS Sequoia for one of the issues. The more severe flaw, CVE-2025-32463, carries a CVSS 9.3 rating and can allow local privilege escalation to root through Sudo’s chroot-related behavior, while CVE-2025-32462 is a lower-severity issue tied to specific sudoers host-matching configurations that can still permit unauthorized command execution as root.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK stated that CVE-2025-32463 was being actively exploited as of 2025-10-01. The update also reiterated the broad platform impact and urged patching or applying workarounds.
The references indicate that updating to sudo 1.9.17p1 or later is the recommended remediation for the disclosed flaws. This establishes the availability of a patched version addressing CVE-2025-32462 and CVE-2025-32463.
Reference content describes two sudo vulnerabilities affecting multiple Unix and Unix-like operating systems. The flaws affect sudo versions prior to 1.9.17p1, with CVE-2025-32463 identified as the more severe issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.