Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
https://www.vicarius.io/vsociety/posts/cve-2025-32463-mitigate-sudo-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2025-32463-detect-sudo-vulnerability
https://www.suse.com/support/update/announcement/2025/suse-su-202502177-1/
https://www.suse.com/security/cve/CVE-2025-32463.html
https://www.openwall.com/lists/oss-security/2025/06/30/3
https://ubuntu.com/security/notices/USN-7604-1
https://security-tracker.debian.org/tracker/CVE-2025-32463
https://explore.alas.aws.amazon.com/CVE-2025-32463.html
https://securelist.com/container-security-typical-issues/119974/
https://thehackernews.com/2025/07/critical-sudo-vulnerabilities-let-local.html
https://www.infosecurity-magazine.com/news/linux-users-urged-to-patch/
https://www.sudo.ws/security/advisories/chroot_bug/
https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
https://github.com/Neverland-lcl/Security_OS_CVE
https://github.com/Neverland-lcl/Security_OS
https://github.com/v3rycl0p3r/CVE-2025-32463
https://github.com/strikoder/LinEnum-ng
https://github.com/wnaspy/CVE-POC-WEAPON
https://github.com/yonathanpy/CVE-2025-32462-CVE-2025-32463-PoC-Lab
https://github.com/zaryouhashraf/CVE-2025-32463
https://github.com/0xAshwesker/CVE-2025-32463
https://github.com/mystichackers/CVE-2025
https://github.com/danilo1992-sys/CVE-2025-32463
https://github.com/SpycioKon/CVE-2025-32463
https://github.com/lakshan-sameera/CVE-2025-32462-and-CVE-2025-32463---Critical-Sudo-Vulnerabilities
https://github.com/justjoeyking/CVE-2025-32463
https://github.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation
https://github.com/kazuke-cva/CVE-2025
https://github.com/NewComrade12211/CVE-2025-32463
https://github.com/DensuLabs/CVE-2025-32463
https://github.com/robbin0919/CVE-2025-32463
https://github.com/cyberajju/CVE-2025-32463
https://github.com/ricardomaia/CVE-2025-32463
https://github.com/harsh1verma/CVE-Analysis
https://github.com/r3dBust3r/CVE-2025-32463
https://github.com/mrudybtw/cveinfobot
https://github.com/zenzue/sudo-CVE-2025-Toolkit
https://github.com/LucaReggiannini/cve2hash
https://github.com/ChetanKomal/sudo_exploit
https://github.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462
https://github.com/daryllundy/CVE-2025-32463
https://github.com/Maalfer/Sudo-CVE-2021-3156
https://github.com/Rajneeshkarya/CVE-2025-32463
https://github.com/Floodnut/CVE-2025-32463
https://github.com/ShaneWan/cve-poc
https://github.com/9Insomnie/CVE-2025-32463
https://github.com/dbarquero/cve-2025-32463-lab
https://github.com/toohau/CVE-2025-32462-32463-Detection-Script-
https://github.com/pevinkumar10/CVE-2025-47812
https://github.com/MAAYTHM/CVE-2025-32462_32463-Lab
https://github.com/Chocapikk/CVE-2025-32463-lab
https://github.com/junxian428/CVE-2025-32463
https://github.com/Ilansos/ansible-sudo-cve2025-patch
https://github.com/CIA911/sudo_patch_CVE-2025-32463
https://github.com/san8383/CVE-2025-32463
https://github.com/neko205-mx/CVE-2025-32463_Exploit
https://github.com/4f-kira/CVE-2025-32463
https://www.sudo.ws/security/advisories/
https://www.sudo.ws/releases/changelog/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32463
Published: 2025-06-30
Updated: 2025-11-05
Known Exploited Vulnerability (KEV)
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.59417
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest