CVE-2025-32463

Publication date 30 June 2025

Last updated 30 September 2025


Ubuntu priority

Cvss 3 Severity Score

9.3 · Critical

Score breakdown

Description

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Why is this CVE high priority?

Allows local privilege escalation

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
sudo 25.04 plucky
Fixed 1.9.16p2-1ubuntu1.1
24.10 oracular
Fixed 1.9.15p5-3ubuntu5.24.10.1
24.04 LTS noble
Fixed 1.9.15p5-3ubuntu5.24.04.1
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.3 · Critical

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities