sudo 1.9.18rc1 released

"Todd C. Miller via sudo-workers" <[email protected]> Sat, 17 Jan 2026 17:19:45 -0700
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
--===============3985200802827862396==
Content-Type: multipart/signed; protocol="application/pgp-signature";
  micalg=pgp-; boundary="57220_Sat_Jan_17_17_19_37_MST_2026"

--57220_Sat_Jan_17_17_19_37_MST_2026
Content-Type: text/plain; charset=us-ascii

The first release candidate for sudo 1.9.18 is now available.
Sudo 1.9.18 is a bug fix release.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.9.18rc1.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.18rc1.tar.gz

SHA256 checksum:
    157cb0b89ee61feebf6fd96c3e5cd24fa40f34ebb2dff41275b1365c8e1b0da4

MD5 checksum:
    77a78d82b788429ac1c3d8b2e1f33747

Binary packages:
    https://www.sudo.ws/getting/beta_packages/

For a list of download mirror sites, see:
    https://www.sudo.ws/getting/download_mirrors/

Sudo web site:
    https://www.sudo.ws/

Major changes between sudo 1.9.18rc1 and 1.9.18b3:

 * Fixed a bug with ksh93 when running a command in a pty with
   the output piped.  ksh93 uses a socketpair instead of a pipe,
   which prevented sudo's heuristic for when to run commands in the
   background from working properly.  This resulted in "stair-stepped"
   output and the terminal settings were not always restored on exit.

 * Fixed a bug parsing sudoers rules where both NOTBEFORE and
   NOTAFTER are set.  A matching NOTAFTER setting would override
   an unmatched NOTBEFORE setting. This was a regression introduced
   in version 1.9.15.

Major changes between sudo 1.9.18b3 and 1.9.18b2:

 * Fixed a problem with AIX authentication when validating the
   password of Kerberos users not present in /etc/security/passwd.

 * Fixed a bug introduced in sudo 1.9.17 when running a command in
   background mode (sudo -b) in a pseudo-terminal.

Major changes between sudo 1.9.18b2 and 1.9.18b1:

 * New Persian (Farsi) translation of sudoers from translationproject.org.

 * Sudo now generates standard version 4 random UUIDs.  Previously
   the type and variant fields were stored in host byte order instead
   of network byte order.

 * Fixed a bug when formatting UUIDs as strings where the '-'
   characters were in the wrong positions.

 * The log ID sent to the client by sudo_logsrvd now includes a
   UUID to prevent ID guessing attacks.  The remaining portion of
   the ID is a path relative to the I/O log dir.  Previously, it
   was an absolute path.

 * Fixed a large number of potential problems found by the ZeroPath
   AI Security Engineer <https://zeropath.com>.

 * Fixed a bug in "sudo -i" where the SHELL variable was set twice
   in the environment.

 * In sudo_logsrvd.conf, the default value for listen_address now
   depends on whether or not TLS has been configured.  If any of the
   TLS options have been enabled, the default is now to enable the
   TLS listener.  Otherwise, the plaintext listener is enabled.
   Previously, the default was to use both a plaintext and TLS listener.

Major changes between sudo 1.9.18b1 and 1.9.17p2:

 * Updated the embedded copy of protobuf-c to version 1.5.2
   and regenerated code from the .proto files.

 * In intercept mode on Linux, the seccomp filter will now kill the
   process if the architecture does not match the native or compatible
   architectures.

 * Fixed a problem in sudoreplay where a speed factor of 0 or less
   would result in a negative delay value that caused a hang during
   playback. Bug #1078.

 * Restored the ability to run "sudo -u myname -g group" when the
   user portion of the Runas_Spec is non-empty and the specified
   group matches the Runas_Spec.  Reported by Marc Schoolderman of
   the sudo-rs project.

 * Fixed a bug with "sudo -U otheruser -l" where the NOPASSWD tag
   was being applied for commands other than "ALL" or "list".  The
   NOPASSWD tag should only be applied when listing another user's
   privileges if the command is "ALL" or "list".  Reported by Marc
   Schoolderman of the sudo-rs project.

 * The "-fcf-protection=full" compiler option is now only used for
   x86_64 CPUs.  For 32-bit x86 CPUs, "-fcf-protection=return" is
   used instead.  This fixes an illegal instruction problem on some
   older Intel-compatible CPUs that do not implement the ENDBR32
   instruction.

 * The sudo_sendlog man page is now only installed when sudo_sendlog
   itself is installed.  GitHub issue #467

 * Sudo now uses most of the suggested compiler and linker options
   from the OpenSSF Compiler Options Hardening Guide for C and C++.

 * Fixed multiple potential crashes in sudo_logsrvd.
   Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
   tool (https://zeropath.com/).

 * Fixed a potential message corruption error in sudo_logsrvd.
   Found by Joshua Rogers (https://joshua.hu) using the ZeroPath
   tool (https://zeropath.com/).

 * Fixed multiple resource leaks on error paths.  Found by Joshua
   Rogers (https://joshua.hu) using the ZeroPath tool
   (https://zeropath.com/).

 * Fixed a potential path traversal bug in sudo_logsrvd when
   restarting an existing log file.  The log ID is used to
   construct the path to the log file and must not contain
   any ".." path components.  Found by Joshua Rogers
   (https://joshua.hu) using the ZeroPath tool (https://zeropath.com/).

 * Fixed a bug in sudo_sendlog that prevented it from transmitting
   older sudo I/O logs that lack a log.json file.

 * sudo_sendlog now verifies the server certificate by default,
   as per the documentation.

 * Fixed a bug that prevented the sending of exit events to the
   sudo log server when I/O logging is not enabled.

 * Fixed a bug that caused sudo-style logs generated by sudo_logsrvd
   to be line-wrapped after 5 characters.

 * When sudo_logsrvd verifies TLS client certificates, it now uses
   the IP address of the peer as well as the DNS hostname, if it
   can be resolved from the address.  Previously, sudo_logsrvd would
   resolve DNS hostnames in the client's certificate to IP addresses
   and compare them to the client IP address.

 * When sudo is logging to a remote log server (sudo_logsrvd),
   if the connection to the server is dropped, the socket is now
   closed immediately.  This fixes an issue when restarting
   sudo_logsrvd on some systems.

 * Fixed a bug that could result in sudo waiting 5 seconds after
   the command exits when logging events, but not I/O, to sudo_logsrvd.

--57220_Sat_Jan_17_17_19_37_MST_2026
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmlsJxkACgkQqfTAIc6k
cPvmAg/+JwOUE8pNSnoZiyDW00/O/3BQeylykTLUeze4AzCBHzOmbErCQe6+e6mE
KFokoSOf4PSJb+4BRsF9M74wBQSyjXjsbdHiPQBg6BXHPk1rOL6kanylRfRPSaxd
liDKqbVanG2Uvf6V6WxglU5bxbxYQUC70Fpp4Ty7cvrtCyV1DivxmSlejn5nEAZ9
vDkBTvDByKcuh744CP5hrkcr/woak4LZXW4m0js2rJvJ6Sg+TmCh3YeZRDyG2fBl
M0d1zVM4U25o++IKlxiqbd1p4qq7qOwTO1hyCnZsIIsCPH4jLUwRTeuC2NKv7ayy
HkyXJZoQTv815X+OYPdvPm600F60T1WzAU7mWob7hqDf8Q+vG7l0fbfbv/5FV4YF
7DCmvDW3QKxMFWAVpwiA2an4x56W5uomxM6AXzpW5eTGS7hg8WtANxo5cZPrA/DA
8c0cGCmhYwCU+ih35+Tn3aj7dP8FdrEgbqsjPAdnJ9hkCu0ORJbgGqY2/Dcm4ntY
GNwjnmd176maxPEBHX1XSqc3ETClGjvAuxS0MiWOmmLzp6XSSN80GuF+0r5wgDuO
z5V/hrFRyzo+f4JJzv8UMLKfbYIEJ7/tlCPVJ8R4tLTWUoHnIwvuJ9IPHfoETXqz
yMjn45m4D1OP1RU1VPU4oTwc1Hn1LS5NiPdGWJ0B/tTsedcfhF8=
=T/UW
-----END PGP SIGNATURE-----

--57220_Sat_Jan_17_17_19_37_MST_2026--


--===============3985200802827862396==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers

--===============3985200802827862396==--