Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4614-1 | sudo security update |
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens sinec Os
|
|
| CPEs | cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Siemens ruggedcom Rst2428p Firmware
|
Siemens sinec Os
|
Tue, 02 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens ruggedcom Rst2428p Siemens ruggedcom Rst2428p Firmware |
|
| CPEs | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:* cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:* cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens ruggedcom Rst2428p Siemens ruggedcom Rst2428p Firmware |
Tue, 02 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Non‑fatal Group Privilege Drop in Sudo | sudo: Sudo: Privilege escalation due to failure in privilege drop calls |
| Weaknesses | CWE-272 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Non‑fatal Group Privilege Drop in Sudo | |
| First Time appeared |
Sudo Project
Sudo Project sudo |
|
| Vendors & Products |
Sudo Project
Sudo Project sudo |
Fri, 03 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. | |
| Weaknesses | CWE-271 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T15:01:58.149Z
Reserved: 2026-04-03T02:21:32.829Z
Link: CVE-2026-35535
Updated: 2026-06-02T13:01:15.329Z
Status : Modified
Published: 2026-04-03T03:16:18.233
Modified: 2026-06-17T10:40:44.057
Link: CVE-2026-35535
OpenCVE Enrichment
Updated: 2026-04-07T07:55:13Z
Debian DLA