Control: tags -1 security upstream wontfix
thanks

On Sun, Aug 30, 2026 at 10:53:06AM +0200, Salvatore Bonaccorso wrote:
> The following vulnerability was published for sudo.
> 
> CVE-2026-82474[0]:
> | Sudo through 1.9.17p2 fails to apply intercept policy checks to the
> | execveat system call in ptrace-based intercept mode. Users permitted
> | to run specific commands can execute denied programs by calling
> | execveat directly or through fexecve, bypassing policy enforcement
> | and logging.
> 
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

We talked about this offline and decided neither to do a DSA nor to pull 
the upstream fix for forky.

Tagging this wontfix, will close it with the next upstream release.

Greetings
Marc

Reply via email to