CVE-2026-35535

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*

History

04 Jun 2026, 16:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/06/msg00003.html -

02 Jun 2026, 17:50

Type Values Removed Values Added
First Time Siemens sinec Os
CPE cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*

02 Jun 2026, 17:41

Type Values Removed Values Added
References () https://bugs.debian.org/1130593 - () https://bugs.debian.org/1130593 - Broken Link
References () https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042 - () https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042 - Issue Tracking
References () https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69 - () https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69 - Patch
References () https://www.qualys.com/2026/03/10/crack-armor.txt - () https://www.qualys.com/2026/03/10/crack-armor.txt - Third Party Advisory
References () https://cert-portal.siemens.com/productcert/html/ssa-253495.html - () https://cert-portal.siemens.com/productcert/html/ssa-253495.html - Third Party Advisory
CPE cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:*
First Time Siemens
Siemens ruggedcom Rst2428p
Sudo Project
Sudo Project sudo
Siemens ruggedcom Rst2428p Firmware

02 Jun 2026, 14:16

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-253495.html -

03 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 03:16

Updated : 2026-06-04 16:16


NVD link : CVE-2026-35535

Mitre link : CVE-2026-35535

CVE.ORG link : CVE-2026-35535


JSON object : View

Products Affected

siemens

  • sinec_os
  • ruggedcom_rst2428p

sudo_project

  • sudo
CWE
CWE-271

Privilege Dropping / Lowering Errors