Security Advisory

CVE-2026-82474

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-29 16:35:33
Last updated 2026-09-02 17:57:15
Assigner VulnCheck
CVSS score 8.5
State PUBLISHED

Description

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.