sudo 1.9.18b1 released

"Todd C. Miller via sudo-workers" <[email protected]> Tue, 07 Oct 2025 09:27:13 -0600
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
--===============1152287814137713116==
Content-Type: multipart/signed; protocol="application/pgp-signature";
  micalg=pgp-; boundary="91946_Tue_Oct__7_09_25_49_MDT_2025"

--91946_Tue_Oct__7_09_25_49_MDT_2025
Content-Type: text/plain; charset=us-ascii

The first beta version of sudo 1.9.18 is now available.
Sudo 1.9.18 is a bug fix release.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.9.18b1.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.18b1.tar.gz

SHA256 checksum:
    fcdf33770a526154b507ad1caae71700f0448128e39475baa6fe8a01cf75c9ad

MD5 checksum:
    32f967227877795aff378f3925bec1d1

Binary packages:
    https://www.sudo.ws/getting/beta_packages/

For a list of download mirror sites, see:
    https://www.sudo.ws/getting/download_mirrors/

Sudo web site:
    https://www.sudo.ws/

Major changes between sudo 1.9.18b1 and 1.9.17p2:

 * Updated the embedded copy of protobuf-c to version 1.5.2
   and regenerated code from the .proto files.

 * In intercept mode on Linux, the seccomp filter will now kill the
   process if the architecture does not match the native or compatible
   architectures.

 * Fixed a problem in sudoreplay where a speed factor of 0 or less
   would result in a negative delay value that caused a hang during
   playback. Bug #1078.

 * Restored the ability to run "sudo -u myname -g group" when the
   user portion of the Runas_Spec is non-empty and the specified
   group matches the Runas_Spec.  Reported by Marc Schoolderman of
   the sudo-rs project.

 * Fixed a bug with "sudo -U otheruser -l" where the NOPASSWD tag
   was being applied for commands other than "ALL" or "list".  The
   NOPASSWD tag should only be applied when listing another user's
   privileges if the command is "ALL" or "list".  Reported by Marc
   Schoolderman of the sudo-rs project.

 * The "-fcf-protection=full" compiler option is now only used for
   x86_64 CPUs.  For 32-bit x86 CPUs, "-fcf-protection=return" is
   used instead.  This fixes an illegal instruction problem on some
   older Intel-compatible CPUs that do not implement the ENDBR32
   instruction.

 * The sudo_sendlog man page is now only installed when sudo_sendlog
   itself is installed.  GitHub issue #467

 * Sudo now uses most of the suggested compiler and linker options
   from the OpenSSF Compiler Options Hardening Guide for C and C++.

 * Fixed multiple potential crashes in sudo_logsrvd.
   Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
   tool (https://zeropath.com/).

 * Fixed a potential message corruption error in sudo_logsrvd.
   Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
   tool (https://zeropath.com/).

 * Fixed multiple resource leaks on error paths.  Found by Joshua
   Rogers (https://joshua.hu) using the ZeroPath tool
   (https://zeropath.com/).

 * Fixed a potential path traversal bug in sudo_logsrvd when
   restarting an existing log file.  The log ID is used to
   construct the path to the log file and must not contain
   any ".." path components.  Found by Joshua Rogers
   (https://joshua.hu) using the ZeroPath tool (https://zeropath.com/).

 * Fixed a bug in sudo_sendlog that prevented it from transmitting
   older sudo I/O logs that lack a log.json file.

 * sudo_sendlog now verifies the server certificate by default,
   as per the documentation.

 * Fixed a bug that prevented the sending of exit events to the
   sudo log server when I/O logging is not enabled.

 * Fixed a bug that caused sudo-style logs generated by sudo_logsrvd
   to be line-wrapped after 5 characters.

 * When sudo_logsrvd verifies TLS client certificates, it now uses
   the IP address of the peer as well as the DNS hostname, if it
   can be resolved from the address.  Previously, sudo_logsrvd would
   resolve DNS hostnames in the client's certificate to IP addresses
   and compare them to the client IP address.

 * When sudo is logging to a remote log server (sudo_logsrvd),
   if the connection to the server is dropped, the socket is now
   closed immediately.  This fixes an issue when restarting
   sudo_logsrvd on some systems.

 * Fixed a bug that could result in sudo waiting 5 seconds after
   the command exits when logging events, but not I/O, to sudo_logsrvd.

--91946_Tue_Oct__7_09_25_49_MDT_2025
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmjlMP0ACgkQqfTAIc6k
cPvVBhAAoNZczXjt3tcHwSD25ktRBvu7wOMQ7UYm8Us9yhYobOQQMynVGKl/bcyb
lkkTmkPjjebNAHdwFW1EGJlPhHMJjwzmKBbXxxMgumJCW2Kx6RmWKERmN6gqkEiQ
TCMBdRuXMzDRgodr/PyN0UGYGpBV3HJcWPXyMGCgEWAEZCKKWrTvNEGYUh5CtucB
wMidWPYzV3yceKXdvSjq6ZXT1YY5cUOjcqDb1eRwvW1pjGGQyvi3MdwOwKJYu9Bw
6NzTjG4kwfOqOhOqMvKlKPpuUhsFpW2XcUBnEj5IVGJcw0jv77nV09c61TEl8SVp
2O32rSiKVbujVzQGG3fYoZu9vo0/9KKxGPEdqkZOL0jOlrKG9O88eLeXoHyZA1qM
v9A0gmDHMZQCeCDsL5H2zw0L+ETnzWKYV/wx2r7kKzL+srZ/twGP6tt17H7WNxBs
mvZ/lDkTEtbkw47N8m/D4k9F09F9anSJ88nkG5oMAFYvZocFobVo28S+RXWC1UvL
Es2h2xfQbZITR6Qv6sWbu7I/PFke/aKLR3VHp046VfJklZZngIrMroX4UgPiAZ6M
x5z8FBy19uk4pYDBdA/kh8RmrUo1Frj/2rvHH/LLuXwv97bRXaXYoq756/9TecYR
uAZyk+PMoIOIwO49cvt3868YS+5F+Rsc5QJ3RZa3IRXtBIA6sFc=
=/1O2
-----END PGP SIGNATURE-----

--91946_Tue_Oct__7_09_25_49_MDT_2025--


--===============1152287814137713116==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers

--===============1152287814137713116==--