In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
References
| Link | Resource |
|---|---|
| https://bugs.debian.org/1130593 | Broken Link |
| https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042 | Issue Tracking |
| https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69 | Patch |
| https://www.qualys.com/2026/03/10/crack-armor.txt | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2026/06/msg00003.html | |
| https://cert-portal.siemens.com/productcert/html/ssa-253495.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
History
04 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Jun 2026, 17:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Siemens sinec Os
|
|
| CPE | cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:* |
02 Jun 2026, 17:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugs.debian.org/1130593 - Broken Link | |
| References | () https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042 - Issue Tracking | |
| References | () https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69 - Patch | |
| References | () https://www.qualys.com/2026/03/10/crack-armor.txt - Third Party Advisory | |
| References | () https://cert-portal.siemens.com/productcert/html/ssa-253495.html - Third Party Advisory | |
| CPE | cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:* cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:* |
|
| First Time |
Siemens
Siemens ruggedcom Rst2428p Sudo Project Sudo Project sudo Siemens ruggedcom Rst2428p Firmware |
02 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
03 Apr 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 03:16
Updated : 2026-06-04 16:16
NVD link : CVE-2026-35535
Mitre link : CVE-2026-35535
CVE.ORG link : CVE-2026-35535
JSON object : View
Products Affected
siemens
- sinec_os
- ruggedcom_rst2428p
sudo_project
- sudo
CWE
CWE-271
Privilege Dropping / Lowering Errors
