CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8708-1: sudo-rs vulnerability

unknown
It was discovered that sudo-rs incorrectly handled time-of-check vs time- of-use conditions in sudoedit. A local attacker with permission to edit specific files using sudoedit could use this issue to place files in arbitrary directories, and possibly escalate their privileges. This issue only affected systems configured to grant fine-grained sudoedit file editing permissions, which is not the default configuration.

CSIRTS triage

What
sudo-rs has a time-of-check vs time-of-use vulnerability in sudoedit allowing placement of files in arbitrary directories.
Who is affected
Systems with fine-grained sudoedit permissions configured (non-default) are affected.
Urgency
Medium urgency as this requires specific non-default sudoedit configuration and local access.
Action
Update sudo-rs to the patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch sudo-rs

Get an email when a new sudo-rs advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-09-01
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8708-1

More from Ubuntu Security Notices