[El-errata] ELSA-2026-75580 Important: Oracle Linux 8 sudo security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Oct 6 18:48:43 UTC 2026
Oracle Linux Security Advisory ELSA-2026-75580
http://linux.oracle.com/errata/ELSA-2026-75580.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
sudo-1.9.5p2-2.0.1.el8_10.x86_64.rpm
aarch64:
sudo-1.9.5p2-2.0.1.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/sudo-1.9.5p2-2.0.1.el8_10.src.rpm
Related CVEs:
CVE-2026-96512
Description of changes:
[1.9.5p2-2.0.1]
- Fixes sudo -s unclosed sessions when use_pty option used [Orabug: 36952911]
[1.9.5p2-2]
RHEL 8.10.0.Z ERRATUM
- CVE-2026-96512 - TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization [rhel-8.10.z]
Resolves: RHEL-267341
[1.9.5p2-1.5]
RHEL 8.10.0.Z ERRATUM
- CVE-2026-35535 - Privilege escalation due to failure in privilege drop calls
Resolves: RHEL-166060
[1.9.5p2-1.3]
RHEL 8.10.0.Z ERRATUM
- sudo passes SHELL environment variable twice to the shell being executed [rhel-8]
Resolves: RHEL-127360
[1.9.5p2-1.2]
RHEL 8.10.0.Z ERRATUM
- Reintroduce cmnd_no_wait
Resolves: RHEL-51956
- Missing separator in the log
Resolves: RHEL-71913
[1.9.5p2-1.1]
RHEL 8.10.0.Z ERRATUM
- CVE-2025-32462 sudo: LPE via host option
Resolves: RHEL-100014
More information about the El-errata
mailing list