CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems
CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

thehackernews.com
CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

Check your version:
sudo --version
As mentioned above, sudo version 1.9.17p1 patches this. This version was already released in June of this year, so many distributions should have it.
On Ubuntu 24.04
Eep!
p5
. The patch was backported.It should be backported in supported ubuntu versions.
Wait, shouldn't Ubuntu 24.04 LTS get security bugfixes?
Its funny because whenever I hear about something like this with foss it tends to be this way but when its proprietary I hear on how they were informed a while back, never patched it, and the founder of the bug is now disclosing based on the timetable they gave the. Feels that way anyway.
Thanks for posting the version.
Looks like Arch updated to this version on 1st July.
My DMZ node had it installed a week later, so I'm all smug today