Sudo's host (`-h` or `--host`) option is intended to be used in conjunction with the list option (`-l` or `--list`) to list a user's sudo privileges on a host other than the current one. However, due to a bug it was not restricted to listing privileges and could be used when running a command via `sudo` or editing a file with `sudoedit`. Depending on the rules present in the sudoers file this could allow a local privilege escalation attack.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9978 https://access.redhat.com/errata/RHSA-2025:9978
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:10110 https://access.redhat.com/errata/RHSA-2025:10110
Dear Team, Related to "Sudo's host (`-h` or `--host`)" While fixing this vulnerability, could you please also correct help information? -h, --help display help message and exit -h, --host=host run command on host (if supported by plugin) Second "-h" should be written with capital letter. Kind regards P.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Extended Update Support EXTENSION Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:10383 https://access.redhat.com/errata/RHSA-2025:10383
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:10518 https://access.redhat.com/errata/RHSA-2025:10518
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:10520 https://access.redhat.com/errata/RHSA-2025:10520
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:10707 https://access.redhat.com/errata/RHSA-2025:10707
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:10779 https://access.redhat.com/errata/RHSA-2025:10779
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:10835 https://access.redhat.com/errata/RHSA-2025:10835
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:10836 https://access.redhat.com/errata/RHSA-2025:10836
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:10871 https://access.redhat.com/errata/RHSA-2025:10871
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:10767 https://access.redhat.com/errata/RHSA-2025:10767
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:10781 https://access.redhat.com/errata/RHSA-2025:10781
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:11537 https://access.redhat.com/errata/RHSA-2025:11537
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:12370 https://access.redhat.com/errata/RHSA-2025:12370
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:12437 https://access.redhat.com/errata/RHSA-2025:12437
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:12323 https://access.redhat.com/errata/RHSA-2025:12323
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:13289 https://access.redhat.com/errata/RHSA-2025:13289
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:10771 https://access.redhat.com/errata/RHSA-2025:10771
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:15672 https://access.redhat.com/errata/RHSA-2025:15672