sudo 1.9.18b2 released
"Todd C. Miller via sudo-workers" <[email protected]> Sun, 23 Nov 2025 16:35:31 -0700
| Newsgroups | gmane.comp.tools.sudo.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============8054433159929878998==
Content-Type: multipart/signed; protocol="application/pgp-signature";
micalg=pgp-; boundary="94020_Sun_Nov_23_16_35_18_MST_2025"
--94020_Sun_Nov_23_16_35_18_MST_2025
Content-Type: text/plain; charset=us-ascii
The second beta version of sudo 1.9.18 is now available.
Sudo 1.9.18 is a bug fix release.
Source:
https://www.sudo.ws/dist/beta/sudo-1.9.18b2.tar.gz
ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.18b2.tar.gz
SHA256 checksum:
eecc815440418337ba7bbe3b03de14fb491acefb2234ca752b0e8035801b6638
MD5 checksum:
c9097061e7b90d99911af966113a5a65
Binary packages:
https://www.sudo.ws/getting/beta_packages/
For a list of download mirror sites, see:
https://www.sudo.ws/getting/download_mirrors/
Sudo web site:
https://www.sudo.ws/
Major changes between sudo 1.9.18b2 and 1.9.18b1:
* New Persian (Farsi) translation of sudoers from translationproject.org.
* Sudo now generates standard version 4 random UUIDs. Previously
the type and variant fields were stored in host byte order instead
of network byte order.
* Fixed a bug when formatting UUIDs as strings where the '-'
characters were in the wrong positions.
* The log ID sent to the client by sudo_logsrvd now includes a
UUID to prevent ID guessing attacks. The remaining portion of
the ID is a path relative to the I/O log dir. Previously, it
was an absolute path.
* Fixed a large number of potential problems found by the ZeroPath
AI Security Engineer <https://zeropath.com>.
* Fixed a bug in "sudo -i" where the SHELL variable was set twice
in the environment.
* In sudo_logsrvd.conf, the default value for listen_address now
depends on whether or not TLS has been configured. If any of the
TLS options have been enabled, the default is now to enable the
TLS listener. Otherwise, the plaintext listener is enabled.
Previously, the default was to use both a plaintext and TLS listener.
Major changes between sudo 1.9.18b1 and 1.9.17p2:
* Updated the embedded copy of protobuf-c to version 1.5.2
and regenerated code from the .proto files.
* In intercept mode on Linux, the seccomp filter will now kill the
process if the architecture does not match the native or compatible
architectures.
* Fixed a problem in sudoreplay where a speed factor of 0 or less
would result in a negative delay value that caused a hang during
playback. Bug #1078.
* Restored the ability to run "sudo -u myname -g group" when the
user portion of the Runas_Spec is non-empty and the specified
group matches the Runas_Spec. Reported by Marc Schoolderman of
the sudo-rs project.
* Fixed a bug with "sudo -U otheruser -l" where the NOPASSWD tag
was being applied for commands other than "ALL" or "list". The
NOPASSWD tag should only be applied when listing another user's
privileges if the command is "ALL" or "list". Reported by Marc
Schoolderman of the sudo-rs project.
* The "-fcf-protection=full" compiler option is now only used for
x86_64 CPUs. For 32-bit x86 CPUs, "-fcf-protection=return" is
used instead. This fixes an illegal instruction problem on some
older Intel-compatible CPUs that do not implement the ENDBR32
instruction.
* The sudo_sendlog man page is now only installed when sudo_sendlog
itself is installed. GitHub issue #467
* Sudo now uses most of the suggested compiler and linker options
from the OpenSSF Compiler Options Hardening Guide for C and C++.
* Fixed multiple potential crashes in sudo_logsrvd.
Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
tool (https://zeropath.com/).
* Fixed a potential message corruption error in sudo_logsrvd.
Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
tool (https://zeropath.com/).
* Fixed multiple resource leaks on error paths. Found by Joshua
Rogers (https://joshua.hu) using the ZeroPath tool
(https://zeropath.com/).
* Fixed a potential path traversal bug in sudo_logsrvd when
restarting an existing log file. The log ID is used to
construct the path to the log file and must not contain
any ".." path components. Found by Joshua Rogers
(https://joshua.hu) using the ZeroPath tool (https://zeropath.com/).
* Fixed a bug in sudo_sendlog that prevented it from transmitting
older sudo I/O logs that lack a log.json file.
* sudo_sendlog now verifies the server certificate by default,
as per the documentation.
* Fixed a bug that prevented the sending of exit events to the
sudo log server when I/O logging is not enabled.
* Fixed a bug that caused sudo-style logs generated by sudo_logsrvd
to be line-wrapped after 5 characters.
* When sudo_logsrvd verifies TLS client certificates, it now uses
the IP address of the peer as well as the DNS hostname, if it
can be resolved from the address. Previously, sudo_logsrvd would
resolve DNS hostnames in the client's certificate to IP addresses
and compare them to the client IP address.
* When sudo is logging to a remote log server (sudo_logsrvd),
if the connection to the server is dropped, the socket is now
closed immediately. This fixes an issue when restarting
sudo_logsrvd on some systems.
* Fixed a bug that could result in sudo waiting 5 seconds after
the command exits when logging events, but not I/O, to sudo_logsrvd.
--94020_Sun_Nov_23_16_35_18_MST_2025
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmkjmjYACgkQqfTAIc6k
cPv+qhAAkOzqzM1SchWy1lghPspAnV+GlMWKUli3/5soGgbJmGu2rzp0zaXZEge0
pJ+n8NOpGo540TPUGZk1VoiAfx1obRpJzvumQ2e+WNwSm13qMCuzLB9H/fN5fGI7
kXJWjJO1Wc+Nu0PxEN0kbTxHr389ERQS4DrwhVKlp7Q6aPdDOfBiTPi/XOa+RLET
7VH8adGYbPJDeFTdtl7SXr9Fo0i+BuzQoBxFcbDJWX1Q++XdiagwSVbYjCOsnXUp
s+soAxQBLTlf17+/RJ966VZfaWEuCpbVmucNEAQO0hL86JkJFByZ1kzxEHgsWB5a
h5jKITPIP3BgB8M69edaSQdrYC1kva10yjzctme03zzXaySdcLOdQiWafsYrpByT
4lcgTw7fk0qpUcNhwFQ9qtXNbKd8pGXdAjSYBLEy1kFTXOxoeqaJbstVsTz4W/E5
mpg1pUWr1/Ox1LzbTtpzsaPhSqpJlu8oFJyNcT+FDYZrdDQF+yLqml2yIepXN7G9
Omq7uwW4ynqPpSqo7B8+50sUa2gFPwswK9MDOmVP4T33a+/xHkH5NtjBNtYUxv7v
DjtUxlCQNc8fwFcJ4HypDsDSzP+3L8cwTl5880OWlPu+/5QlKKvo607B31l2NDY3
L+J+3TYBM3jQL9RFIVODgWeqOfcz8HR2layPh5y27jKAzFGbEyY=
=GJDi
-----END PGP SIGNATURE-----
--94020_Sun_Nov_23_16_35_18_MST_2025--
--===============8054433159929878998==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers
--===============8054433159929878998==--