RaqibCTI
CVE

CVE-2025-32463

P2
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Sudo · Sudo
Date added (CISA)
2025-09-29
Remediation due
2025-10-20
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

Source: NVD ↗ · CISA KEV Catalog ↗