Critical Sudo bugs have been discovered that allow local users to gain root access on Linux systems.
The vulnerabilities, named CVE-2025-32462 and CVE-2025-32463, affect major Linux distributions.
CVE-2025-32462 allows executing commands on unintended machines, while CVE-2025-32463 lets local users obtain root access through user-controlled directories.
The Stratascale Cyber Research Unit found the vulnerabilities, with a fix limiting the --host option and deprecating the chroot feature in Sudo.