[ALSA-2026:75579] Important: sudo security update
Type:
security
Severity:
important
Release date:
2026-10-06
Description:
The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: sudo: TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization (CVE-2026-96512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 sudo-python-plugin-1.9.17-10.p2.el10_2.7.aarch64.rpm cddeb2aa376046c28129cd3d4146fe9222477a42e77ac018dbf0a479e1a7b717
aarch64 sudo-1.9.17-10.p2.el10_2.7.aarch64.rpm e9ba1ff396107fb284887838e9917f110e206278cfb1a7e7b6cbe27fa8984eb3
ppc64le sudo-1.9.17-10.p2.el10_2.7.ppc64le.rpm 4fdf442ef0159531c0a014e54cbc33e239e8ecc0b4b8335c97936221049960b2
ppc64le sudo-python-plugin-1.9.17-10.p2.el10_2.7.ppc64le.rpm 99dd2de1e1990d7cf007963051c67128370b93265a31fd70cc77d9674d67f2ac
s390x sudo-python-plugin-1.9.17-10.p2.el10_2.7.s390x.rpm 8d6988fe8c9a1c8b7d7445d47a241d1e1ea026f19640b0f1485cea20b7fc74ea
s390x sudo-1.9.17-10.p2.el10_2.7.s390x.rpm d37cec6b58e614853d04dd57e972d948e5cd4d2377a043d5e87c28274fa522af
x86_64 sudo-1.9.17-10.p2.el10_2.7.x86_64.rpm 62c4bc8faf31801c8d1df0540690202b5e6b675bc67d171e7e75b4a6b4a58f39
x86_64 sudo-python-plugin-1.9.17-10.p2.el10_2.7.x86_64.rpm b26fad75a54b7fa89821a0f218e4f62c865220d375ce635f192abb6ed3dc22f6
x86_64_v2 sudo-python-plugin-1.9.17-10.p2.el10_2.7.x86_64_v2.rpm 4377464b2b26a84a1cf4d1722a7dd1c025bb6f8f27b6bc259dace3b0984c0fc8
x86_64_v2 sudo-1.9.17-10.p2.el10_2.7.x86_64_v2.rpm d9c534b91dc0b832254f8f6d9b9fc3bb6d4ab5f463f4abb7184a35c343c05304
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.