[ALSA-2026:68692] Important: sudo security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-09-18
Description:
The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: Sudo: Policy bypass allows unauthorized program execution via execveat (CVE-2026-82474) Bug Fix(es) and Enhancement(s): * Use canonicalized path if user path contains ".." (JIRA:AlmaLinux-212546) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 sudo-python-plugin-1.9.17-10.p2.el10_2.6.aarch64.rpm 69a79c3cb3c150ed8fcd40bd0db8569297342f211ab1c76b60664e5ba90c3615
aarch64 sudo-1.9.17-10.p2.el10_2.6.aarch64.rpm d7286770de0f277299078cd079e66c94161404be3a4d955c2938ab95d3c583a4
ppc64le sudo-python-plugin-1.9.17-10.p2.el10_2.6.ppc64le.rpm 43bdea08defbaf5dd4c0dfb3572ae3e1f58b8f557c1c6af46c7493a6d6f5b6e7
ppc64le sudo-1.9.17-10.p2.el10_2.6.ppc64le.rpm 5fac3fe2e370afe623bc87320249a53031e124bb4650fe8d11e781efca0adce3
s390x sudo-python-plugin-1.9.17-10.p2.el10_2.6.s390x.rpm 26849cf9f5b59abfc6249ac151fdf467147308dce31b2da88f87431f261b37b8
s390x sudo-1.9.17-10.p2.el10_2.6.s390x.rpm c14d099387555123bb2caf54ffe9077584ae54b7b917351d8d0ff348c0310968
x86_64 sudo-python-plugin-1.9.17-10.p2.el10_2.6.x86_64.rpm 9c9dd2e748b3205af1a515deb18cfd26aae08ce795c296b5be49ad228e2a75dd
x86_64 sudo-1.9.17-10.p2.el10_2.6.x86_64.rpm f2a234941e85f45d1481c9597b0ae4b0f7265fc0fc92f3485200e60ddcca4bad
x86_64_v2 sudo-1.9.17-10.p2.el10_2.6.x86_64_v2.rpm 0fa1bcc7a3c8757dfbd8e302f768c185efc1dc66fbe33064cb5cdbfce5ed2450
x86_64_v2 sudo-python-plugin-1.9.17-10.p2.el10_2.6.x86_64_v2.rpm 42821780ea9c77fff5de9b0b602ca8cb9ce392c3b58e288dcea27df5aec64221
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.