Home / mailings [USN-8708-1] sudo-rs vulnerability
Posted on 01 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8708-1
September 01, 2026
rust-sudo-rs vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
sudo-rs could be made to run programs as an administrator.
Software Description:
- rust-sudo-rs: Rust-based sudo and su implementations
Details:
It was discovered that sudo-rs incorrectly handled time-of-check vs time-
of-use conditions in sudoedit. A local attacker with permission to edit
specific files using sudoedit could use this issue to place files in
arbitrary directories, and possibly escalate their privileges. This issue
only affected systems configured to grant fine-grained sudoedit file
editing permissions, which is not the default configuration.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
sudo-rs 0.2.13-0ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8708-1
https://bugs.launchpad.net/bugs/2165142
Package Information:
https://launchpad.net/ubuntu/+source/rust-sudo-rs/0.2.13-0ubuntu1.2
--===============7179256678053903083==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
