CVE-2025-32463HIGH 7.8CISA KEVEPSS p98.7%
CVE-2025-32463Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Sudo / Sudo
Description
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.
Scoring
| CVSS 3.1 | 7.8 (HIGH) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 48.01% probability of exploitation · percentile 98.7% · 2026-06-18T12:00:27Z |
| Published | 2025-06-30 |
| Last modified | 2025-11-05 |
CISA KEV entry
Added to KEV: 2025-09-29
Underlying weaknesses· 1
References
- https://access.redhat.com/security/cve/cve-2025-32463
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463
- https://explore.alas.aws.amazon.com/CVE-2025-32463.html
- https://security-tracker.debian.org/tracker/CVE-2025-32463
- https://ubuntu.com/security/notices/USN-7604-1
- https://www.openwall.com/lists/oss-security/2025/06/30/3
- https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/
- https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Inclusion of Functionality from Untrusted Control Spherecwe-829 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerabilitykev-cve-2025-32463 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.