Vulnerabilities

sudo on Linux: which version fixes what

sudo has a short vulnerability list by the standards of this page. It also has the highest stakes: a bug in sudo is, by definition, a path from a local account to root.

SecAI tracks 50 distinct CVEs affecting sudo across the 6 distributions below, of which 4 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

sudo is how an unprivileged user runs a command as another user, usually root. It is setuid root, which means it starts with full privilege and is responsible for giving it up correctly.

Why its advisories behave the way they do

  • Every sudo flaw is a privilege escalation. There is no such thing as a low-impact sudo advisory, which is why the named ones, like Baron Samedit and the 2023 chown bug, get so much attention.
  • It turns any foothold into full compromise. A web shell running as www-data is contained; the same web shell on a host with an exploitable sudo is not.
  • The sudoers file is a second attack surface. Rules that permit a wildcard path, or a command that can spawn a shell, hand out root without any CVE being involved at all.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' sudo 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q sudo

Run `sudo -l` as each account that has any sudo access. A rule ending in a wildcard, or naming an editor or an interpreter, is usually a full root grant in disguise.

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: sudo

CVEPublishedFixed in package version
CVE-2026-965122026-09-24no fixed version released
CVE-2026-355352026-04-031.9.9-1ubuntu2.6
CVE-2025-324622025-06-301.9.9-1ubuntu2.5
CVE-2025-324632025-06-301.9.9-1ubuntu2.5
CVE-2023-284862023-04-111.9.9-1ubuntu2.4
CVE-2023-284872023-04-111.9.9-1ubuntu2.4
CVE-2023-273202023-03-021.9.9-1ubuntu2.3
CVE-2023-228092023-01-181.9.9-1ubuntu2.2
CVE-2022-330702023-01-181.9.9-1ubuntu2.2

Showing the 9 most recent of 9 that apply to Ubuntu 22.04 LTS, 1 of which have no fixed version released.

Ubuntu 24.04 LTSsource package: sudo

CVEPublishedFixed in package version
CVE-2026-965122026-09-24no fixed version released
CVE-2026-824742026-09-221.9.15p5-3ubuntu5.24.04.3
CVE-2026-355352026-04-031.9.15p5-3ubuntu5.24.04.2
CVE-2025-324622025-06-301.9.15p5-3ubuntu5.24.04.1
CVE-2025-324632025-06-301.9.15p5-3ubuntu5.24.04.1

Showing the 5 most recent of 5 that apply to Ubuntu 24.04 LTS, 1 of which have no fixed version released.

Debian 12 (bookworm)source package: sudo

CVEPublishedFixed in package version
CVE-2026-965122026-09-23no fixed version released
CVE-2026-824742026-08-29no fixed version released
CVE-2026-355352026-04-031.9.13p3-1+deb12u4
CVE-2025-324622025-06-301.9.13p3-1+deb12u2
CVE-2023-70902023-12-231.8.28p1-1
CVE-2023-424652023-12-22no fixed version released
CVE-2023-284862023-03-161.9.13p1-1
CVE-2023-284872023-03-161.9.13p1-1
CVE-2023-273202023-02-281.9.13p3-1
CVE-2023-228092023-01-181.9.12p2-1
CVE-2022-439952022-11-021.9.12p1-1
CVE-2021-31562021-01-261.9.5p1-1.1
CVE-2021-232392021-01-121.9.5-1
CVE-2021-232402021-01-121.9.5-1
CVE-2019-186342020-01-291.8.31-1
CVE-2019-192322019-12-191.8.31-1
CVE-2019-192342019-12-191.8.31-1
CVE-2005-48902019-11-041.7.4p4
CVE-2019-142872019-10-171.8.27-1.1
CVE-2016-70762018-05-291.8.18p1-1
CVE-2015-82392017-10-101.8.17p1-1
CVE-2017-10003672017-06-051.8.20p1-1
CVE-2017-10003682017-06-051.8.20p1-1.1
CVE-2014-96802017-04-241.8.12-1
CVE-2016-70322017-04-141.8.15-1

Showing the 25 most recent of 48 that apply to Debian 12 (bookworm), 4 of which have no fixed version released.

Debian 13 (trixie)source package: sudo

CVEPublishedFixed in package version
CVE-2026-965122026-09-23no fixed version released
CVE-2026-824742026-08-29no fixed version released
CVE-2026-355352026-04-031.9.16p2-3+deb13u2
CVE-2025-324622025-06-301.9.16p2-3
CVE-2025-324632025-06-301.9.16p2-3
CVE-2023-70902023-12-231.8.28p1-1
CVE-2023-424652023-12-221.9.15p2-2
CVE-2023-284862023-03-161.9.13p1-1
CVE-2023-284872023-03-161.9.13p1-1
CVE-2023-273202023-02-281.9.13p3-1
CVE-2023-228092023-01-181.9.12p2-1
CVE-2022-439952022-11-021.9.12p1-1
CVE-2021-31562021-01-261.9.5p1-1.1
CVE-2021-232392021-01-121.9.5-1
CVE-2021-232402021-01-121.9.5-1
CVE-2019-186342020-01-291.8.31-1
CVE-2019-192322019-12-191.8.31-1
CVE-2019-192342019-12-191.8.31-1
CVE-2005-48902019-11-041.7.4p4
CVE-2019-142872019-10-171.8.27-1.1
CVE-2016-70762018-05-291.8.18p1-1
CVE-2015-82392017-10-101.8.17p1-1
CVE-2017-10003672017-06-051.8.20p1-1
CVE-2017-10003682017-06-051.8.20p1-1.1
CVE-2014-96802017-04-241.8.12-1

Showing the 25 most recent of 49 that apply to Debian 13 (trixie), 3 of which have no fixed version released.

Rocky Linux 9source package: sudo

CVEPublishedFixed in package version
CVE-2026-824742026-09-220:1.9.17p2-3.el9_8.1
CVE-2026-355352026-05-280:1.9.17p2-3.el9_8
CVE-2025-324622025-10-040:1.9.5p2-10.el9_6.1
CVE-2023-228092023-01-230:1.9.5p2-7.el9_1.1

Showing the 4 most recent of 4 that apply to Rocky Linux 9.

AlmaLinux 9source package: sudo

CVEPublishedFixed in package version
CVE-2026-824742026-09-211.9.17p2-3.el9_8.1
CVE-2026-355352026-05-191.9.17p2-3.el9_8
CVE-2025-324622025-06-301.9.5p2-10.el9_6.1
CVE-2023-284862024-02-141.9.5p2-10.el9_3
CVE-2023-284872024-02-141.9.5p2-10.el9_3
CVE-2023-424652024-02-141.9.5p2-10.el9_3
CVE-2023-228092023-01-231.9.5p2-7.el9_1.1

Showing the 7 most recent of 7 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, sudo included. It changes nothing.