Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions debian/changelog
Original file line number Diff line number Diff line change
@@ -1,3 +1,10 @@
sudo (1.9.16p2-3deepin2) unstable; urgency=medium

* Fix CVE-2026-35535: exec_mailer: Set group as well as uid when
running the mailer.

-- deepin-ci-robot <packages@deepin.org> Mon, 13 Apr 2026 21:24:10 +0800

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Whom? Which LLM is used to generate this PR?


sudo (1.9.16p2-3deepin1) unstable; urgency=medium

[ zhouzilong ]
Expand Down
141 changes: 141 additions & 0 deletions debian/patches/cve_2026_35535.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,141 @@
Description: exec_mailer: Set group as well as uid when running the mailer.
Also make a setuid(), setgid() or setgroups() failure fatal.
Author: Todd C. Miller <Todd.Miller@sudo.ws>
Origin: upstream
Bug: https://security-tracker.debian.org/tracker/CVE-2026-35535
Forwarded: not-needed
Last-Update: 2026-04-13
---
include/sudo_eventlog.h | 3 ++-
lib/eventlog/eventlog.c | 21 +++++++++++++++++----
lib/eventlog/eventlog_conf.c | 4 +++-
plugins/sudoers/logging.c | 2 +-
plugins/sudoers/policy.c | 2 +-
5 files changed, 24 insertions(+), 8 deletions(-)
Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h
===================================================================
--- github-sudo-CVE-2026-35535.orig/include/sudo_eventlog.h
+++ github-sudo-CVE-2026-35535/include/sudo_eventlog.h
@@ -80,6 +80,7 @@ struct eventlog_config {
int syslog_rejectpri;
int syslog_alertpri;
uid_t mailuid;
+ gid_t mailgid;
bool omit_hostname;
const char *logpath;
const char *time_fmt;
@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int p
void eventlog_set_syslog_alertpri(int pri);
void eventlog_set_syslog_maxlen(size_t len);
void eventlog_set_file_maxlen(size_t len);
-void eventlog_set_mailuid(uid_t uid);
+void eventlog_set_mailuser(uid_t uid, gid_t gid);
void eventlog_set_omit_hostname(bool omit_hostname);
void eventlog_set_logpath(const char *path);
void eventlog_set_time_fmt(const char *fmt);
Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog.c
+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c
@@ -304,15 +304,13 @@ exec_mailer(int pipein)
syslog(LOG_ERR, _("unable to dup stdin: %m")); // -V618
sudo_debug_printf(SUDO_DEBUG_ERROR,
"unable to dup stdin: %s", strerror(errno));
- sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);
- _exit(127);
+ goto bad;
}

/* Build up an argv based on the mailer path and flags */
if ((mflags = strdup(evl_conf->mailerflags)) == NULL) {
syslog(LOG_ERR, _("unable to allocate memory")); // -V618
- sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);
- _exit(127);
+ goto bad;
}
argv[0] = sudo_basename(mpath);

@@ -331,11 +329,23 @@ exec_mailer(int pipein)
if (setuid(ROOT_UID) != 0) {
sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change uid to %u",
ROOT_UID);
+ goto bad;
+ }
+ if (setgid(evl_conf->mailgid) != 0) {
+ sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change gid to %u",
+ (unsigned int)evl_conf->mailgid);
+ goto bad;
+ }
+ if (setgroups(1, &evl_conf->mailgid) != 0) {
+ sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to set groups to %u",
+ (unsigned int)evl_conf->mailgid);
+ goto bad;
}
if (evl_conf->mailuid != ROOT_UID) {
if (setuid(evl_conf->mailuid) != 0) {
sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change uid to %u",
(unsigned int)evl_conf->mailuid);
+ goto bad;
}
}
sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);
@@ -347,6 +357,9 @@ exec_mailer(int pipein)
sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to execute %s: %s",
mpath, strerror(errno));
_exit(127);
+bad:
+ sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);
+ _exit(127);
}

/* Send a message to the mailto user */
Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog_conf.c
+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c
@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf =
MAXSYSLOGLEN, /* syslog_maxlen */
0, /* file_maxlen */
ROOT_UID, /* mailuid */
+ ROOT_GID, /* mailgid */
false, /* omit_hostname */
_PATH_SUDO_LOGFILE, /* logpath */
"%h %e %T", /* time_fmt */
@@ -151,9 +152,10 @@ eventlog_set_file_maxlen(size_t len)
}

void
-eventlog_set_mailuid(uid_t uid)
+eventlog_set_mailuser(uid_t uid, gid_t gid)
{
evl_conf.mailuid = uid;
+ evl_conf.mailgid = gid;
}

void
Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/logging.c
+++ github-sudo-CVE-2026-35535/plugins/sudoers/logging.c
@@ -1155,7 +1155,7 @@ init_eventlog_config(void)
eventlog_set_syslog_alertpri(def_syslog_badpri);
eventlog_set_syslog_maxlen(def_syslog_maxlen);
eventlog_set_file_maxlen(def_loglinelen);
- eventlog_set_mailuid(ROOT_UID);
+ eventlog_set_mailuser(ROOT_UID, ROOT_GID);
eventlog_set_omit_hostname(!def_log_host);
eventlog_set_logpath(def_logfile);
eventlog_set_time_fmt(def_log_year ? "%h %e %T %Y" : "%h %e %T");
Index: github-sudo-CVE-2026-35535/plugins/sudoers/policy.c
===================================================================
--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/policy.c
+++ github-sudo-CVE-2026-35535/plugins/sudoers/policy.c
@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct s
}

#ifdef NO_ROOT_MAILER
- eventlog_set_mailuid(ctx->user.uid);
+ eventlog_set_mailuser(ctx->user.uid, ctx->user.gid);
#endif

/* Dump settings and user info (XXX - plugin args) */
1 change: 1 addition & 0 deletions debian/patches/series
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,4 @@ X11R6.patch
0007-upstream-patch-for-CVE-2025-32463.patch
0008-upstream-patch-for-CVE-2025-32462.patch
developer-mode-verify.patch
cve_2026_35535.patch
Loading