Authentication Bypass Vulnerability in sudo-rs by Trifecta Tech Foundation
CVE-2025-64517
4.4MEDIUM
What is CVE-2025-64517?
The sudo-rs software, a secure implementation of the sudo command, contains a vulnerability that affects its functionality related to user authentication. When the Defaults targetpw or Defaults rootpw settings are enabled, the system improperly records the invoking user's UID instead of the target user's UID in the authentication timestamp. This flaw allows a highly-privileged user to execute commands on behalf of other accounts without knowing their passwords, effectively circumventing intended security policies. Users running versions 0.2.5 to 0.2.9 of sudo-rs are at risk, with the issue resolved in version 0.2.10.
Affected Version(s)
sudo-rs >= 0.2.5, < 0.2.10
