USN-7867-1: sudo-rs vulnerabilities
ubuntu.com·3h·
Discuss: Hacker News
Flag this post

Publication date

10 November 2025

Overview

Several security issues were fixed in sudo-rs.

Releases


Packages

Details

It was discovered that sudo-rs incorrectly handled passwords when timeouts occurred and the pwfeedback default was not set. This could result in a partially typed password being output to standard input, contrary to expectations.

It was discovered that sudo-rs incorrectly handled the targetpw and rootpw default settings when creating timestamp files. A local attacker could possibly use this issue to bypass authentication i…

Similar Posts

Loading similar posts...