Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-32463
Score elevated to 9.3 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-09-29), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.3 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 9.3
- EG Score
- 9.3(high)
- EG Risk
- 82(Attend)EG Risk 82/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity93% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 59%
- EPSS %ILE
- 99%
- KEV
- ⚠ Exploited
Published
June 30, 2025
Last Modified
November 5, 2025
Advisory Details (10)
Auto-updated Aug 26, 2026Sudo LPE Vulnerabilities Resolved: What You Need to Know About CVE-202 | SecPod
https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/oss-security - CVE-2025-32463: sudo local privilege escalation via chroot option
https://www.openwall.com/lists/oss-security/2025/06/30/3USN-7604-1: Sudo vulnerabilities | Ubuntu security notices | Ubuntu
Affected: Ubuntu 24.04 LTS, Ubuntu 24.10, and
https://ubuntu.com/security/notices/USN-7604-1959314 – (CVE-2025-32462, CVE-2025-32463) <app-admin/sudo-1.9.17_p1: two local privilege escalation vulnerabilities
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463CVE-2025-32463 - Red Hat Customer Portal
Affected: Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to a
https://access.redhat.com/security/cve/cve-2025-32463Sudo chroot elevation of privilege | Stratascale
https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chrootVendor Advisories for CVE-2025-32463(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | sudo-ldap (1.9.16p2-1ubuntu1.1) @ plucky | 2026-09-05 | ubuntu |
| redhat | sudo-0:1.9.15-8.p5.el10_0.2 | 2025-07-22 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(2 across 2 ecosystems)
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| sudo | — | 1.9.16p2-3 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| sudo | — | 1.9.16p2-3 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(2)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 87× in last 7d / 375× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 1,196 total refreshes for this CVE.
- 2026-09-05 09:46 UTCVendor advisory
- 2026-09-05 09:46 UTCGHSA enrichment
- 2026-09-05 05:22 UTCVendor advisory
- 2026-09-05 05:22 UTCGHSA enrichment
- 2026-09-05 00:57 UTCVendor advisory
- 2026-09-05 00:57 UTCGHSA enrichment
- 2026-09-04 20:30 UTCVendor advisory
- 2026-09-04 20:30 UTCGHSA enrichment
- 2026-09-04 17:38 UTCCISA KEV update
- 2026-09-04 16:06 UTCEG score recompute
- 2026-09-04 16:06 UTCVendor advisory
- 2026-09-04 16:06 UTCGHSA enrichment
- 2026-09-04 11:42 UTCVendor advisory
- 2026-09-04 11:42 UTCGHSA enrichment
- 2026-09-04 07:17 UTCVendor advisory
- 2026-09-04 07:17 UTCGHSA enrichment
- 2026-09-04 02:53 UTCVendor advisory
- 2026-09-04 02:53 UTCGHSA enrichment
- 2026-09-03 22:28 UTCVendor advisory
- 2026-09-03 22:28 UTCGHSA enrichment
- 2026-09-03 18:03 UTCVendor advisory
- 2026-09-03 18:03 UTCGHSA enrichment
- 2026-09-03 13:36 UTCVendor advisory
- 2026-09-03 13:36 UTCGHSA enrichment
- 2026-09-03 09:10 UTCVendor advisory
Show 75 moreShow fewer
- 2026-09-03 09:10 UTCGHSA enrichment
- 2026-09-03 04:45 UTCVendor advisory
- 2026-09-03 04:45 UTCGHSA enrichment
- 2026-09-03 00:20 UTCVendor advisory
- 2026-09-03 00:20 UTCGHSA enrichment
- 2026-09-02 19:54 UTCVendor advisory
- 2026-09-02 19:54 UTCGHSA enrichment
- 2026-09-02 17:33 UTCCISA KEV update
- 2026-09-02 15:30 UTCEG score recompute
- 2026-09-02 15:30 UTCVendor advisory
- 2026-09-02 15:29 UTCGHSA enrichment
- 2026-09-02 14:11 UTCEPSS rescore
- 2026-09-02 11:05 UTCVendor advisory
- 2026-09-02 11:05 UTCGHSA enrichment
- 2026-09-02 06:41 UTCVendor advisory
- 2026-09-02 06:40 UTCGHSA enrichment
- 2026-09-02 02:16 UTCVendor advisory
- 2026-09-02 02:16 UTCGHSA enrichment
- 2026-09-01 21:48 UTCVendor advisory
- 2026-09-01 21:48 UTCGHSA enrichment
- 2026-09-01 17:24 UTCVendor advisory
- 2026-09-01 17:23 UTCGHSA enrichment
- 2026-09-01 12:59 UTCVendor advisory
- 2026-09-01 12:59 UTCGHSA enrichment
- 2026-09-01 08:34 UTCVendor advisory
- 2026-09-01 08:34 UTCGHSA enrichment
- 2026-09-01 04:06 UTCVendor advisory
- 2026-09-01 04:06 UTCGHSA enrichment
- 2026-08-31 23:41 UTCVendor advisory
- 2026-08-31 23:41 UTCGHSA enrichment
- 2026-08-31 19:17 UTCVendor advisory
- 2026-08-31 19:16 UTCGHSA enrichment
- 2026-08-31 14:52 UTCVendor advisory
- 2026-08-31 14:52 UTCGHSA enrichment
- 2026-08-31 14:19 UTCCISA KEV update
- 2026-08-31 10:26 UTCVendor advisory
- 2026-08-31 10:26 UTCGHSA enrichment
- 2026-08-31 06:02 UTCVendor advisory
- 2026-08-31 06:02 UTCGHSA enrichment
- 2026-08-31 01:37 UTCVendor advisory
- 2026-08-31 01:37 UTCGHSA enrichment
- 2026-08-30 21:13 UTCEG score recompute
- 2026-08-30 21:13 UTCVendor advisory
- 2026-08-30 21:13 UTCGHSA enrichment
- 2026-08-30 19:16 UTCEPSS rescore
- 2026-08-30 19:16 UTCEPSS rescore
- 2026-08-30 16:49 UTCVendor advisory
- 2026-08-30 16:49 UTCGHSA enrichment
- 2026-08-30 12:25 UTCVendor advisory
- 2026-08-30 12:25 UTCGHSA enrichment
- 2026-08-30 08:01 UTCVendor advisory
- 2026-08-30 08:01 UTCGHSA enrichment
- 2026-08-30 03:37 UTCEG score recompute
- 2026-08-30 03:37 UTCVendor advisory
- 2026-08-30 03:37 UTCGHSA enrichment
- 2026-08-30 01:21 UTCEPSS rescore
- 2026-08-29 23:13 UTCVendor advisory
- 2026-08-29 23:12 UTCGHSA enrichment
- 2026-08-29 18:46 UTCVendor advisory
- 2026-08-29 18:46 UTCGHSA enrichment
- 2026-08-29 14:21 UTCVendor advisory
- 2026-08-29 14:21 UTCGHSA enrichment
- 2026-08-29 09:57 UTCVendor advisory
- 2026-08-29 09:57 UTCGHSA enrichment
- 2026-08-29 05:33 UTCVendor advisory
- 2026-08-29 05:32 UTCGHSA enrichment
- 2026-08-29 01:07 UTCEG score recompute
- 2026-08-29 01:07 UTCVendor advisory
- 2026-08-29 01:06 UTCGHSA enrichment
- 2026-08-28 21:40 UTCEPSS rescore
- 2026-08-28 20:41 UTCVendor advisory
- 2026-08-28 20:40 UTCGHSA enrichment
- 2026-08-28 16:15 UTCVendor advisory
- 2026-08-28 16:15 UTCGHSA enrichment
- 2026-08-28 11:51 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC1xPwn/CVE-2025-32463First seen Aug 8, 2025
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Open source ↗ - GitHub PoCNowafen/CVE-2025-32463First seen Aug 8, 2025
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Open source ↗ - GitHub PoCAdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462First seen Jul 21, 2025
A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.
Open source ↗ - GitHub PoCMohamedKarrab/CVE-2025-32463First seen Jul 14, 2025
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
Open source ↗ - Exploit-DBEDB-52352First seen Jul 8, 2025
Sudo chroot 1.9.17 - Local Privilege Escalation
Open source ↗ - GitHub PoCK3ysTr0K3R/CVE-2025-32463-EXPLOITFirst seen Jul 6, 2025
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
Open source ↗ - GitHub PoCzinzloun/CVE-2025-32463First seen Jul 4, 2025
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
Open source ↗ - GitHub PoCmirchr/CVE-2025-32463-sudo-chwootFirst seen Jul 3, 2025
PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability
Open source ↗ - GitHub PoCkh4sh3i/CVE-2025-32463First seen Jul 2, 2025
Local Privilege Escalation to Root via Sudo chroot in Linux
Open source ↗ - GitHub PoCK1tt3h/CVE-2025-32463-POCFirst seen Jul 1, 2025
CVE-2025-32463 Proof of concept
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat
- CVE-2001-0825EG 10.0HIGH
- CVE-2001-0554EG 10.0EPSS p98HIGH
- CVE-2001-0414EG 10.0EPSS p100HIGH
- CVE-2001-0191EG 10.0EPSS p92HIGH
- CVE-2001-0301EG 10.0EPSS p91HIGH
- CVE-2001-0197EG 10.0EPSS p96HIGH
- CVE-2001-0233EG 10.0EPSS p96HIGH
- CVE-2001-0010EG 10.0EPSS p98HIGH
- CVE-2001-0011EG 10.0EPSS p94HIGH
- CVE-2001-0013EG 10.0EPSS p96HIGH
Same CWE
10 shownCWE-829
- CVE-2021-41037EG 10.0CRITICAL
- CVE-2022-1161EG 10.0EPSS p92CRITICAL
- CVE-2020-4561EG 10.0CRITICAL
- CVE-2022-24119EG 9.8CRITICAL
- CVE-2020-16152EG 9.8EPSS p98CRITICAL
- CVE-2021-21804EG 9.8CRITICAL
- CVE-2020-25414EG 9.8CRITICAL
- CVE-2020-3794EG 9.8EPSS p94CRITICAL
- CVE-2020-8128EG 9.8CRITICAL
- CVE-2012-4919EG 9.8CRITICAL
Frequently asked(6)
What is CVE-2025-32463?
When was CVE-2025-32463 disclosed?
Is CVE-2025-32463 actively exploited?
What is the CVSS score of CVE-2025-32463?
Which products are affected by CVE-2025-32463?
How do I remediate CVE-2025-32463?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-32463
Is Your Infrastructure Affected by CVE-2025-32463?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.