Control: tags -1 security upstream wontfix thanks On Sun, Aug 30, 2026 at 10:53:06AM +0200, Salvatore Bonaccorso wrote: > The following vulnerability was published for sudo. > > CVE-2026-82474[0]: > | Sudo through 1.9.17p2 fails to apply intercept policy checks to the > | execveat system call in ptrace-based intercept mode. Users permitted > | to run specific commands can execute denied programs by calling > | execveat directly or through fexecve, bypassing policy enforcement > | and logging. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
We talked about this offline and decided neither to do a DSA nor to pull the upstream fix for forky. Tagging this wontfix, will close it with the next upstream release. Greetings Marc

