CVE-2025-32463: Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2025-09-29. EPSS: 55.5% chance of exploitation in the next 30 days.

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Affected products

  • Canonical Ubuntu Linux: version 22.04 only; version 24.04 only; version 24.10 only; version 25.04 only
  • Debian Debian Linux: version 11.0 only; version 12.0 only; version 13.0 only
  • Opensuse Leap: version 15.6 only
  • Red Hat Enterprise Linux: version 10.0 only
  • Sudo Project Sudo: from 1.9.14, before 1.9.17 (fixed in 1.9.17); version 1.9.17 only
  • Suse Linux Enterprise Desktop: version 15 only
  • Suse Linux Enterprise Real Time: version 15.0 only
  • Suse Linux Enterprise Server For SAP: version 12 only

Published 2025-06-30. Last modified 2026-06-17.