Hi Marc,

On Mon, Aug 31, 2026 at 07:38:35PM +0200, Marc Haber wrote:
> Control: tags -1 security upstream wontfix
> thanks
> 
> On Sun, Aug 30, 2026 at 10:53:06AM +0200, Salvatore Bonaccorso wrote:
> > The following vulnerability was published for sudo.
> > 
> > CVE-2026-82474[0]:
> > | Sudo through 1.9.17p2 fails to apply intercept policy checks to the
> > | execveat system call in ptrace-based intercept mode. Users permitted
> > | to run specific commands can execute denied programs by calling
> > | execveat directly or through fexecve, bypassing policy enforcement
> > | and logging.
> > 
> > 
> > If you fix the vulnerability please also make sure to include the
> > CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> We talked about this offline and decided neither to do a DSA nor to pull 
> the upstream fix for forky.
> 
> Tagging this wontfix, will close it with the next upstream release.

I have marked the issue as unimportant in the security-tracker and
once a new upstream version includes the fix and this bug is closed we
will simply update the unstable version tracking along.

Regards,
Salvatore

Reply via email to