The sudo chroot escalation: a local root bug in the one program whose job is to hand out root carefully
A flaw in sudo's handling of an option most administrators have never used, exploitable by a local user who has no sudo rights at all. CISA added it to the Known Exploited catalogue in September 2025.
A fixed package version is available on 3 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
sudo supports running a command inside a chroot the user names. Handling that option, sudo loads configuration from inside the user-controlled directory while still holding root privilege, so the user decides what root reads and acts on.
What an attacker gets: Full root from an ordinary local account. Notably, it does not require the account to be listed in sudoers at all.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It applies to sudo built with the chroot feature, which is the default in the packages below.
- No sudo permission is needed by the attacker. This is unusual: most sudo flaws require an existing rule to abuse, and this one does not.
- Local only, so it is an escalation from an existing foothold rather than a way in.
Check your own server
sudo --version | head -1Prints the sudo version. Compare the package version below, since the fix is backported.
If you cannot patch today
Where the package cannot be updated immediately, a sudoers rule setting `Defaults !use_pty` does not help; there is no configuration that removes this one. Patching is the answer.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | sudo | Fixed | 1.9.9-1ubuntu2.5 |
| Ubuntu 24.04 LTS | sudo | Fixed | 1.9.15p5-3ubuntu5.24.04.1 |
| Debian 12 (bookworm) | sudo | No advisory names it | no advisory for this release names it |
| Debian 13 (trixie) | sudo | Fixed | 1.9.16p2-3 |
| Rocky Linux 9 | sudo | No advisory names it | no advisory for this release names it |
| AlmaLinux 9 | sudo | No advisory names it | no advisory for this release names it |
Install the fix with apt update && apt install --only-upgrade sudo on Debian and Ubuntu, or dnf update sudo on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Recorded from nvd. Its weakness class is CWE-829, from NVD.
- https://access.redhat.com/security/cve/cve-2025-32463
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463
- https://explore.alas.aws.amazon.com/CVE-2025-32463.html
- https://security-tracker.debian.org/tracker/CVE-2025-32463
- https://ubuntu.com/security/notices/USN-7604-1
- https://www.openwall.com/lists/oss-security/2025/06/30/3
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2025-32463 included. It changes nothing.