Home / mailingsPDF  

[USN-8708-1] sudo-rs vulnerability

Posted on 01 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8708-1
September 01, 2026

rust-sudo-rs vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS

Summary:

sudo-rs could be made to run programs as an administrator.

Software Description:
- rust-sudo-rs: Rust-based sudo and su implementations

Details:

It was discovered that sudo-rs incorrectly handled time-of-check vs time-
of-use conditions in sudoedit. A local attacker with permission to edit
specific files using sudoedit could use this issue to place files in
arbitrary directories, and possibly escalate their privileges. This issue
only affected systems configured to grant fine-grained sudoedit file
editing permissions, which is not the default configuration.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
sudo-rs 0.2.13-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8708-1
https://bugs.launchpad.net/bugs/2165142

Package Information:
https://launchpad.net/ubuntu/+source/rust-sudo-rs/0.2.13-0ubuntu1.2

--===============7179256678053903083==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP