[CLSA-2026:1790600964] sudo: Fix of 7 CVEs
Type:
security
Severity:
None
Release date:
2026-09-28 13:09:33 UTC
Description:
- Rebase onto the vendor's sudo-1.8.23-10.0.3.el7_9.3 sources - CVE-2025-32462: take the vendor's fix, keep our audit record of the rejected remote host - CVE-2026-35535 is now fixed by the vendor (sudo-1.8.23-CVE-2026-35535.patch); the TuxCare duplicate is dropped - Retained TuxCare fixes: CVE-2021-23239, CVE-2021-23240, CVE-2023-28486, CVE-2023-28487, CVE-2023-42465
Updated packages:
  • sudo-1.8.23-10.0.3.el7_9.3.tuxcare.els1.i686.rpm
    sha:817f82629276b524dc6dbb092708ef52e994fa1746d0833492c1e11e796bcdf6
  • sudo-1.8.23-10.0.3.el7_9.3.tuxcare.els1.x86_64.rpm
    sha:c5a301f9e5090702ed9cb90b15e62a5ee5851b6e7b1d739da9bece3113877895
  • sudo-devel-1.8.23-10.0.3.el7_9.3.tuxcare.els1.i686.rpm
    sha:74ac21dbabdee95389ae387a4800e1a7a6eae06295f37f7013b033ed776c4677
  • sudo-devel-1.8.23-10.0.3.el7_9.3.tuxcare.els1.x86_64.rpm
    sha:c2ee0add3bf61294a38e1bd602343f701456b1b21c6113724076a84e75d21424
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.