Hi Marc, On Mon, Aug 31, 2026 at 07:38:35PM +0200, Marc Haber wrote: > Control: tags -1 security upstream wontfix > thanks > > On Sun, Aug 30, 2026 at 10:53:06AM +0200, Salvatore Bonaccorso wrote: > > The following vulnerability was published for sudo. > > > > CVE-2026-82474[0]: > > | Sudo through 1.9.17p2 fails to apply intercept policy checks to the > > | execveat system call in ptrace-based intercept mode. Users permitted > > | to run specific commands can execute denied programs by calling > > | execveat directly or through fexecve, bypassing policy enforcement > > | and logging. > > > > > > If you fix the vulnerability please also make sure to include the > > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > We talked about this offline and decided neither to do a DSA nor to pull > the upstream fix for forky. > > Tagging this wontfix, will close it with the next upstream release.
I have marked the issue as unimportant in the security-tracker and once a new upstream version includes the fix and this bug is closed we will simply update the unstable version tracking along. Regards, Salvatore

