Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 13 additions & 8 deletions debian/changelog
Original file line number Diff line number Diff line change
@@ -1,16 +1,21 @@
sudo (1.9.16p2-3deepin2) unstable; urgency=medium
sudo (1.9.16p2-3+deb13u2) trixie; urgency=medium

* Fix CVE-2026-35535: exec_mailer: Set group as well as uid when
running the mailer.
* cherry-pick upstream exec_mailer-Set-group-as-well-as-uid.
This is upstream and fixes CVE-2026-35535:
https://github.com/sudo-project/sudo/commit/3e474c2 (Closes: #1130593)

-- deepin-ci-robot <packages@deepin.org> Mon, 13 Apr 2026 21:24:10 +0800
-- Marc Haber <mh+debian-packages@zugschlus.de> Sat, 11 Apr 2026 14:21:02 +0200

sudo (1.9.16p2-3deepin1) unstable; urgency=medium
sudo (1.9.16p2-3+deb13u1) trixie; urgency=medium

[ zhouzilong ]
* add develper mode verify message.
[ Marc Haber ]
* add upstream patch: Do not perform path expansion
Thanks to Adam D. Barratt" <adam@adam-barratt.org.uk> (Closes: #1126085)
* Enable Intel CET on amd64 only.
Thanks to Marcos Del Sol Vives (Closes: #1124339)
* Pull more robust test suite from unstable

-- Tianyu Chen <sweetyfish@deepin.org> Mon, 30 Jun 2025 23:01:07 +0800
-- Marc Haber <mh+debian-packages@zugschlus.de> Wed, 11 Feb 2026 20:22:01 +0100

sudo (1.9.16p2-3) unstable; urgency=high

Expand Down
Original file line number Diff line number Diff line change
@@ -1,21 +1,22 @@
Description: exec_mailer: Set group as well as uid when running the mailer.
Also make a setuid(), setgid() or setgroups() failure fatal.
Author: Todd C. Miller <Todd.Miller@sudo.ws>
Origin: upstream
Bug: https://security-tracker.debian.org/tracker/CVE-2026-35535
Forwarded: not-needed
Last-Update: 2026-04-13
From: "Todd C. Miller" <Todd.Miller@sudo.ws>
Date: Sat, 8 Nov 2025 15:34:02 -0700
Subject: exec_mailer: Set group as well as uid when running the mailer

Also make a setuid(), setgid() or setgroups() failure fatal.

Found by the ZeroPath AI Security Engineer <https://zeropath.com>
---
include/sudo_eventlog.h | 3 ++-
lib/eventlog/eventlog.c | 21 +++++++++++++++++----
lib/eventlog/eventlog_conf.c | 4 +++-
plugins/sudoers/logging.c | 2 +-
plugins/sudoers/policy.c | 2 +-
5 files changed, 24 insertions(+), 8 deletions(-)
Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h
===================================================================
--- github-sudo-CVE-2026-35535.orig/include/sudo_eventlog.h
+++ github-sudo-CVE-2026-35535/include/sudo_eventlog.h

diff --git a/include/sudo_eventlog.h b/include/sudo_eventlog.h
index eb9f4f4..485d259 100644
--- a/include/sudo_eventlog.h
+++ b/include/sudo_eventlog.h
@@ -80,6 +80,7 @@ struct eventlog_config {
int syslog_rejectpri;
int syslog_alertpri;
Expand All @@ -24,7 +25,7 @@ Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h
bool omit_hostname;
const char *logpath;
const char *time_fmt;
@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int p
@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int pri);
void eventlog_set_syslog_alertpri(int pri);
void eventlog_set_syslog_maxlen(size_t len);
void eventlog_set_file_maxlen(size_t len);
Expand All @@ -33,10 +34,10 @@ Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h
void eventlog_set_omit_hostname(bool omit_hostname);
void eventlog_set_logpath(const char *path);
void eventlog_set_time_fmt(const char *fmt);
Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog.c
+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c
diff --git a/lib/eventlog/eventlog.c b/lib/eventlog/eventlog.c
index 5a32824..d56c4e4 100644
--- a/lib/eventlog/eventlog.c
+++ b/lib/eventlog/eventlog.c
@@ -304,15 +304,13 @@ exec_mailer(int pipein)
syslog(LOG_ERR, _("unable to dup stdin: %m")); // -V618
sudo_debug_printf(SUDO_DEBUG_ERROR,
Expand Down Expand Up @@ -89,11 +90,11 @@ Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c
}

/* Send a message to the mailto user */
Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog_conf.c
+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c
@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf =
diff --git a/lib/eventlog/eventlog_conf.c b/lib/eventlog/eventlog_conf.c
index 0663a38..ec3b569 100644
--- a/lib/eventlog/eventlog_conf.c
+++ b/lib/eventlog/eventlog_conf.c
@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf = {
MAXSYSLOGLEN, /* syslog_maxlen */
0, /* file_maxlen */
ROOT_UID, /* mailuid */
Expand All @@ -113,11 +114,11 @@ Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c
}

void
Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/logging.c
+++ github-sudo-CVE-2026-35535/plugins/sudoers/logging.c
@@ -1155,7 +1155,7 @@ init_eventlog_config(void)
diff --git a/plugins/sudoers/logging.c b/plugins/sudoers/logging.c
index bd4de92..9535289 100644
--- a/plugins/sudoers/logging.c
+++ b/plugins/sudoers/logging.c
@@ -1157,7 +1157,7 @@ init_eventlog_config(void)
eventlog_set_syslog_alertpri(def_syslog_badpri);
eventlog_set_syslog_maxlen(def_syslog_maxlen);
eventlog_set_file_maxlen(def_loglinelen);
Expand All @@ -126,11 +127,11 @@ Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c
eventlog_set_omit_hostname(!def_log_host);
eventlog_set_logpath(def_logfile);
eventlog_set_time_fmt(def_log_year ? "%h %e %T %Y" : "%h %e %T");
Index: github-sudo-CVE-2026-35535/plugins/sudoers/policy.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/policy.c
+++ github-sudo-CVE-2026-35535/plugins/sudoers/policy.c
@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct s
diff --git a/plugins/sudoers/policy.c b/plugins/sudoers/policy.c
index f3adfb0..27f6e58 100644
--- a/plugins/sudoers/policy.c
+++ b/plugins/sudoers/policy.c
@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct sudoers_context *ctx, void *v,
}

#ifdef NO_ROOT_MAILER
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
From: "Todd C. Miller" <Todd.Miller@sudo.ws>
Date: Sat, 24 Jan 2026 11:30:06 -0700
Subject: open_sudoers: Do not perform path expansion on files in an
includedir

A file in an includedir containing one or more colons (':') in the
name we was being expanded as a colon-separated path instead of
being opened as-is. This fixes a regression introduced in
sudo 1.9.14. Bug #1085
---
plugins/sudoers/sudoers.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)

diff --git a/plugins/sudoers/sudoers.c b/plugins/sudoers/sudoers.c
index 0f75c96..fecd279 100644
--- a/plugins/sudoers/sudoers.c
+++ b/plugins/sudoers/sudoers.c
@@ -1286,7 +1286,15 @@ open_sudoers(const char *path, char **outfile, bool doedit, bool *keepopen)
int error, fd;
debug_decl(open_sudoers, SUDOERS_DEBUG_PLUGIN);

- fd = sudo_open_conf_path(path, fname, sizeof(fname), open_file);
+ if (outfile == NULL) {
+ /* Single file, do not treat as a path. */
+ fd = open_file(path, O_RDONLY|O_NONBLOCK);
+ if (fd != -1)
+ (void)fcntl(fd, F_SETFL, fcntl(fd, F_GETFL, 0) & ~O_NONBLOCK);
+ } else {
+ /* Could be a colon-separated path of file names. */
+ fd = sudo_open_conf_path(path, fname, sizeof(fname), open_file);
+ }
if (sudoers_ctx.parser_conf.ignore_perms) {
/* Skip sudoers security checks when ignore_perms is set. */
if (fd == -1 || fstat(fd, &sb) == -1)
28 changes: 28 additions & 0 deletions debian/patches/amd64-ibt.diff
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
From: Marcos Del Sol Vives <marcos@orca.pet>
Date: Tue, 2 Sep 2025 00:00:35 +0200
Subject: Enable Intel CET on amd64 only

---
m4/hardening.m4 | 2 ++
1 file changed, 2 insertions(+)

diff --git a/m4/hardening.m4 b/m4/hardening.m4
index f7d2a8c..cc7ee01 100644
--- a/m4/hardening.m4
+++ b/m4/hardening.m4
@@ -105,6 +105,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [
])
fi

+ if test "$host_cpu" = "x86_64"; then
# Check for control-flow transfer instrumentation (Intel CET).
AX_CHECK_COMPILE_FLAG([-fcf-protection], [
AX_CHECK_LINK_FLAG([-fcf-protection], [
@@ -112,6 +113,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [
AX_APPEND_FLAG([-Wc,-fcf-protection], [HARDENING_LDFLAGS])
])
])
+ fi
fi

# Linker-specific hardening flags.
87 changes: 0 additions & 87 deletions debian/patches/developer-mode-verify.patch

This file was deleted.

5 changes: 3 additions & 2 deletions debian/patches/series
Original file line number Diff line number Diff line change
Expand Up @@ -5,5 +5,6 @@ sudo-ldap-docs.patch
X11R6.patch
0007-upstream-patch-for-CVE-2025-32463.patch
0008-upstream-patch-for-CVE-2025-32462.patch
developer-mode-verify.patch
cve_2026_35535.patch
0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch
amd64-ibt.diff
0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch
4 changes: 2 additions & 2 deletions debian/tests/01-getroot
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ passwd1=$(echo "$passwd" |cut -c1)
# Note: we do need the 'xfoo' syntax here, since POSIX special-cases
# the $passwd value '!' as negation.
if [ "x$passwd" = "x*" ] || [ "x$passwd1" = "x!" ]; then
echo "root:rootpassword" | chpasswd
echo "root:riegh@oh4ahR" | chpasswd
fi

TESTNR="01"
Expand All @@ -19,7 +19,7 @@ DIR="${BASEDIR}/${TESTNR}"
PATH="/bin:/usr/bin:/sbin:/usr/sbin"
ACCTA="test${TESTNR}a"
ACCTB="test${TESTNR}b"
PASSWD="test${TESTNR}23456"
PASSWD="test${TESTNR}Terah9ien7e"
HOMEDIRA="/home/${ACCTA}"
HOMEDIRB="/home/${ACCTB}"
LDIFDIR="${DIR}/ldif"
Expand Down
26 changes: 17 additions & 9 deletions debian/tests/02-1003969-audit-no-resolve
Original file line number Diff line number Diff line change
Expand Up @@ -7,21 +7,29 @@ BASEDIR="$(pwd)/debian/tests"
COMMONDIR="${BASEDIR}/common"
DIR="${BASEDIR}/${TESTNR}"
PATH="/bin:/usr/bin:/sbin:/usr/sbin"
ACCTA="test${TESTNR}a"
ACCTB="test${TESTNR}b"
PASSWD="test${TESTNR}23456"
HOMEDIRA="/root"
LDIFDIR="${DIR}/ldif"

trap '
printf "\ntrap handler\n"
mv /etc/resolv.conf.disabled /etc/resolv.conf || true
mv /etc/hosts.disabled /etc/hosts || true
if [ -e /etc/resolv.conf.disabled ]; then
cp /etc/resolv.conf.disabled /etc/resolv.conf || true
rm -f /etc/resolv.conf.disabled || true
fi
if [ -e /etc/hosts.disabled ]; then
cp /etc/hosts.disabled /etc/hosts || true
rm -f /etc/hosts.disabled || true
fi
' 0 INT QUIT ABRT PIPE TERM

printf "========= test %s\.1: sudo to nobody\n" "${TESTNR}"
mv /etc/resolv.conf /etc/resolv.conf.disabled
mv /etc/hosts /etc/hosts.disabled
if [ -e /etc/resolv.conf ]; then
cp /etc/resolv.conf /etc/resolv.conf.disabled
: >/etc/resolv.conf
fi
if [ -e /etc/hosts ]; then
cp /etc/hosts /etc/hosts.disabled
: >/etc/hosts
fi
RET=0
printf "trying sudo to nobody\n"
cd "${HOMEDIRA}"
Expand All @@ -35,7 +43,7 @@ if [ "${STDERRLENGTH}" != "0" ]; then
printf >&2 "stderr:\n"
cat >&2 ${HOMEDIRA}/stderr
printf >&2 "exit code %s\n" "${RET}"
printf >&2 "exit 1\n" "${RET}"
printf >&2 "exit 1\n"
exit 1
fi

Expand Down
32 changes: 32 additions & 0 deletions debian/tests/03-1126085-sudoersd
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
#!/bin/sh

set -e

TESTNR="03"
BASEDIR="$(pwd)/debian/tests"
COMMONDIR="${BASEDIR}/common"
DIR="${BASEDIR}/${TESTNR}"
PATH="/bin:/usr/bin:/sbin:/usr/sbin"
FILES="$(find $DIR/sudoersd/ -type f)"
echo $FILES
DSTFILES="$(echo $FILES | sed "s|${DIR}/sudoersd|/etc/sudoers.d|g")"
echo $DSTFILES

trap '
true
' 0 INT QUIT ABRT PIPE TERM

printf "copy files to sudoers ... "
cp $FILES /etc/sudoers.d/
printf "collect sudo -l output ... "
OUTPUT="$(sudo -l | grep -- ----marker----)"
EXPECTED=" (ALL : ALL) /usr/bin/----marker----/this-is-the-sudoersd-10_dsa\:\:util\:\:sudo[dfsg-team-role]-file
(ALL : ALL) /usr/bin/----marker----/this-is-the-sudoersd-root-file"
if [ "$OUTPUT" != "$EXPECTED" ]; then
printf "sudo -l output not as expected, Test failed\n"
exit 1
fi

printf "test series sucessful, exit 0\n"
exit 0

1 change: 1 addition & 0 deletions debian/tests/03/10_dsa::util::sudo[dfsg-team-role]
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
root ALL=(ALL:ALL) /usr/bin/----marker----/this-is-the-sudoersd-10_dsa\:\:util\:\:sudo[dfsg-team-role]-file
Loading
Loading