Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-32463
Score elevated to 9.3 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-09-29), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.3 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 9.3
- EG Score
- 9.3(high)
- EG Risk
- 82(Attend)EG Risk 82/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity93% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 59%
- EPSS %ILE
- 99%
- KEV
- ⚠ Exploited
Published
June 30, 2025
Last Modified
November 5, 2025
Advisory Details (10)
Auto-updated Sep 15, 2026Sudo LPE Vulnerabilities Resolved: What You Need to Know About CVE-202 | SecPod
https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/oss-security - CVE-2025-32463: sudo local privilege escalation via chroot option
https://www.openwall.com/lists/oss-security/2025/06/30/3USN-7604-1: Sudo vulnerabilities | Ubuntu security notices | Ubuntu
Affected: Ubuntu 24.04 LTS, Ubuntu 24.10, and
https://ubuntu.com/security/notices/USN-7604-1959314 – (CVE-2025-32462, CVE-2025-32463) <app-admin/sudo-1.9.17_p1: two local privilege escalation vulnerabilities
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463CVE-2025-32463 - Red Hat Customer Portal
Affected: Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to a
https://access.redhat.com/security/cve/cve-2025-32463Sudo chroot elevation of privilege | Stratascale
https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chrootVendor Advisories for CVE-2025-32463(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | sudo-ldap (1.9.9-1ubuntu2.5) @ jammy | 2026-09-19 | ubuntu |
| redhat | sudo-0:1.9.15-8.p5.el10_0.2 | 2025-07-22 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(2 across 2 ecosystems)
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| sudo | — | 1.9.16p2-3 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| sudo | — | 1.9.16p2-3 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(2)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 92× in last 7d / 388× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 1,382 total refreshes for this CVE.
- 2026-09-19 08:49 UTCVendor advisory
- 2026-09-19 08:49 UTCGHSA enrichment
- 2026-09-19 04:22 UTCVendor advisory
- 2026-09-19 04:22 UTCGHSA enrichment
- 2026-09-18 23:58 UTCVendor advisory
- 2026-09-18 23:58 UTCGHSA enrichment
- 2026-09-18 19:34 UTCEG score recompute
- 2026-09-18 19:34 UTCVendor advisory
- 2026-09-18 19:34 UTCGHSA enrichment
- 2026-09-18 19:27 UTCEPSS rescore
- 2026-09-18 19:20 UTCCISA KEV update
- 2026-09-18 15:10 UTCVendor advisory
- 2026-09-18 15:09 UTCGHSA enrichment
- 2026-09-18 14:15 UTCCISA KEV update
- 2026-09-18 10:45 UTCVendor advisory
- 2026-09-18 10:45 UTCGHSA enrichment
- 2026-09-18 06:21 UTCVendor advisory
- 2026-09-18 06:21 UTCGHSA enrichment
- 2026-09-18 01:57 UTCVendor advisory
- 2026-09-18 01:57 UTCGHSA enrichment
- 2026-09-17 21:32 UTCEG score recompute
- 2026-09-17 21:32 UTCVendor advisory
- 2026-09-17 21:32 UTCGHSA enrichment
- 2026-09-17 17:08 UTCVendor advisory
- 2026-09-17 17:07 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-09-17 12:40 UTCVendor advisory
- 2026-09-17 12:40 UTCGHSA enrichment
- 2026-09-17 08:11 UTCVendor advisory
- 2026-09-17 08:11 UTCGHSA enrichment
- 2026-09-17 03:46 UTCVendor advisory
- 2026-09-17 03:46 UTCGHSA enrichment
- 2026-09-16 23:22 UTCVendor advisory
- 2026-09-16 23:22 UTCGHSA enrichment
- 2026-09-16 18:58 UTCVendor advisory
- 2026-09-16 18:58 UTCGHSA enrichment
- 2026-09-16 14:34 UTCEG score recompute
- 2026-09-16 14:34 UTCVendor advisory
- 2026-09-16 14:34 UTCGHSA enrichment
- 2026-09-16 14:10 UTCCISA KEV update
- 2026-09-16 14:07 UTCEPSS rescore
- 2026-09-16 10:10 UTCVendor advisory
- 2026-09-16 10:09 UTCGHSA enrichment
- 2026-09-16 05:46 UTCEG score recompute
- 2026-09-16 05:46 UTCVendor advisory
- 2026-09-16 05:46 UTCGHSA enrichment
- 2026-09-16 05:13 UTCEPSS rescore
- 2026-09-16 01:22 UTCVendor advisory
- 2026-09-16 01:22 UTCGHSA enrichment
- 2026-09-15 20:58 UTCVendor advisory
- 2026-09-15 20:58 UTCGHSA enrichment
- 2026-09-15 16:34 UTCVendor advisory
- 2026-09-15 16:34 UTCGHSA enrichment
- 2026-09-15 12:10 UTCVendor advisory
- 2026-09-15 12:10 UTCGHSA enrichment
- 2026-09-15 07:46 UTCVendor advisory
- 2026-09-15 07:46 UTCGHSA enrichment
- 2026-09-15 03:21 UTCEG score recompute
- 2026-09-15 03:21 UTCVendor advisory
- 2026-09-15 03:21 UTCGHSA enrichment
- 2026-09-14 22:57 UTCVendor advisory
- 2026-09-14 22:57 UTCGHSA enrichment
- 2026-09-14 19:24 UTCCISA KEV update
- 2026-09-14 18:32 UTCVendor advisory
- 2026-09-14 18:32 UTCGHSA enrichment
- 2026-09-14 14:08 UTCVendor advisory
- 2026-09-14 14:08 UTCGHSA enrichment
- 2026-09-14 09:44 UTCVendor advisory
- 2026-09-14 09:43 UTCGHSA enrichment
- 2026-09-14 05:19 UTCVendor advisory
- 2026-09-14 05:19 UTCGHSA enrichment
- 2026-09-14 00:55 UTCVendor advisory
- 2026-09-14 00:55 UTCGHSA enrichment
- 2026-09-13 20:31 UTCEG score recompute
- 2026-09-13 20:31 UTCVendor advisory
- 2026-09-13 20:31 UTCGHSA enrichment
- 2026-09-13 16:46 UTCEPSS rescore
- 2026-09-13 16:07 UTCVendor advisory
- 2026-09-13 16:07 UTCGHSA enrichment
- 2026-09-13 11:42 UTCVendor advisory
- 2026-09-13 11:42 UTCGHSA enrichment
- 2026-09-13 07:17 UTCVendor advisory
- 2026-09-13 07:17 UTCGHSA enrichment
- 2026-09-13 02:54 UTCVendor advisory
- 2026-09-13 02:53 UTCGHSA enrichment
- 2026-09-12 22:30 UTCVendor advisory
- 2026-09-12 22:30 UTCGHSA enrichment
- 2026-09-12 18:05 UTCEG score recompute
- 2026-09-12 18:05 UTCVendor advisory
- 2026-09-12 18:05 UTCGHSA enrichment
- 2026-09-12 15:00 UTCEPSS rescore
- 2026-09-12 13:41 UTCVendor advisory
- 2026-09-12 13:41 UTCGHSA enrichment
- 2026-09-12 09:17 UTCVendor advisory
- 2026-09-12 09:17 UTCGHSA enrichment
- 2026-09-12 04:53 UTCVendor advisory
- 2026-09-12 04:53 UTCGHSA enrichment
- 2026-09-12 00:29 UTCVendor advisory
- 2026-09-12 00:29 UTCGHSA enrichment
- 2026-09-11 20:05 UTCVendor advisory
- 2026-09-11 20:05 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC1xPwn/CVE-2025-32463First seen Aug 8, 2025
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Open source ↗ - GitHub PoCNowafen/CVE-2025-32463First seen Aug 8, 2025
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Open source ↗ - GitHub PoCAdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462First seen Jul 21, 2025
A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.
Open source ↗ - GitHub PoCMohamedKarrab/CVE-2025-32463First seen Jul 14, 2025
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
Open source ↗ - Exploit-DBEDB-52352First seen Jul 8, 2025
Sudo chroot 1.9.17 - Local Privilege Escalation
Open source ↗ - GitHub PoCK3ysTr0K3R/CVE-2025-32463-EXPLOITFirst seen Jul 6, 2025
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
Open source ↗ - GitHub PoCzinzloun/CVE-2025-32463First seen Jul 4, 2025
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
Open source ↗ - GitHub PoCmirchr/CVE-2025-32463-sudo-chwootFirst seen Jul 3, 2025
PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability
Open source ↗ - GitHub PoCkh4sh3i/CVE-2025-32463First seen Jul 2, 2025
Local Privilege Escalation to Root via Sudo chroot in Linux
Open source ↗ - GitHub PoCK1tt3h/CVE-2025-32463-POCFirst seen Jul 1, 2025
CVE-2025-32463 Proof of concept
Open source ↗
Frequently asked(6)
What is CVE-2025-32463?
When was CVE-2025-32463 disclosed?
Is CVE-2025-32463 actively exploited?
What is the CVSS score of CVE-2025-32463?
Which products are affected by CVE-2025-32463?
How do I remediate CVE-2025-32463?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-32463
Is Your Infrastructure Affected by CVE-2025-32463?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.