← Retour
CVE-2026-82474
high
CVSS 7.8
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Résumé
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-82474** a été découverte dans linux.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 7.8/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « linux CVE-2026-82474 » sur le site de l'éditeur.
CVE-2026-82474 (linux) — CWE-693 / CVSS v3 7.8
Vecteur d'attaque : local / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Sudoのptraceベースのインターセプトモードにおけるポリシーチェックの不備。
📍 Périmètre concerné
Sudo 1.9.17p2までのバージョン。
🔥 Gravité
許可されていないプログラムの実行を可能にし、ポリシーとロギングをバイパスする点で、重大な影響を及ぼす可能性がある。
🔧 Comment corriger
最新のSudoバージョンを使用し、脆弱性を修正したバージョンに更新する。
🛡️ Contournement
暫定的な回避策は情報なし。
🔍 Détection
システム内で不正なプログラム実行の痕跡を調査する。
Références
- web https://github.com/sudo-project/sudo
- web https://github.com/sudo-project/sudo/blob/v1.9.17p2/src/exec_ptrace.c
- web https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
- web https://www.vulncheck.com/advisories/sudo-through-1.9-17p2-intercept-policy-bypass-via-execveat
- web https://nvd.nist.gov/vuln/detail/CVE-2026-82474
- web https://github.com/advisories/GHSA-36m7-65w5-jm6c