CVE-2025-32463Patch(canonical / debian_linux)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch canonical debian_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-829

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • enterprise_linux
  • leap
  • linux_enterprise_desktop

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-20); latest day: 1
  • 13 total mentions across 9 days

Affected systems

Products
debian_linuxenterprise_linuxleaplinux_enterprise_desktoplinux_enterprise_real_timelinux_enterprise_server_for_sapsudoubuntu_linux

13 versions affected across 8 products

Deep dive

Activity timeline13 mentions / 9d
01223Mentions · 2026-02-04: 2Mentions · 2026-02-12: 2Mentions · 2026-03-07: 1Mentions · 2026-03-30: 1Mentions · 2026-04-13: 1Mentions · 2026-05-01: 1Mentions · 2026-05-20: 3Mentions · 2026-06-22: 1Mentions · 2026-07-02: 1PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-05-20: 2PoC Mentioned / Linked · 2026-06-22: 1PoC Mentioned / Linked · 2026-07-02: 1Exploit Tool / Code · 2026-05-20: 2Exploit Tool / Code · 2026-06-22: 1Exploit Tool / Code · 2026-07-02: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-02-04: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-30: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-02: 102-0402-1203-0703-3004-1305-0105-2006-2207-02
Signal classification4 categories
Patch
538.5%
PoC
430.8%
General
323.1%
Exploit
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-042
Patch2
2026-02-122
General1Patch1
2026-03-071
PoC1
2026-03-301
General1
2026-04-131
General1
2026-05-011
Patch1
2026-05-203
Patch1PoC2
2026-06-221
PoC1
2026-07-021
Exploit1
Full discourse13 posts
  • Nicolas Krassas@Dinosn
    Exploit

    o-based exploit tool for CVE-2025-32463, a critical local privilege escalation vulnerability (CVSS 9.3) in sudo versions 1.9.14 to 1.9.17. https://github.com/Nowafen/CVE-2025-32463

    Post summary

    An exploit tool for CVE-2025-32463, a critical LPE in sudo, has been released on GitHub; no active exploitation or patch info is provided.

    024094447.6K
    160.8K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - Nowafen/CVE-2025-32463: This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access. · GitHub https://github.com/Nowafen/CVE-2025-32463

    Post summary

    The GitHub repo provides a proof‑of‑concept for CVE‑2025‑32463, a sudo local privilege escalation flaw, with no evidence of active exploitation or patch availability.

    0803094.7K
    63.3K followersView on X
  • ♛DowntownRob♛@DowntownRob
    Patch

    @elormkdaniel This is old from 2025, CVE-2025-32463, and has been patched in sudo 1.9.15p5-3ubuntu5.24.04.1: https://ubuntu.com/security/CVE-2025-32463

    Post summary

    The tweet references CVE-2025-32463 and confirms it has been patched, offering a link to the vendor advisory for details.

    0201353.9K
    9.7K followersView on X
  • Justin Andrusk@jandrusk
    PoC

    @elormkdaniel @nyxgeek https://github.com/K1tt3h/CVE-2025-32463-POC

    Post summary

    The tweet references a GitHub repository named CVE-2025-32463-POC, indicating that a proof‑of‑concept exploit script is publicly available, with no mention of active exploitation, patches, or detailed technical information.

    010771.1K
    3.8K followersView on X
  • Bob (Moderna #8) Kerns@BobKerns
    PoC

    @utdream @elormkdaniel https://github.com/K1tt3h/CVE-2025-32463-POC/blob/main/CVE-2025-32463-POC.sh

    Post summary

    A tweet links to a GitHub proof‑of‑concept script for CVE‑2025‑32463, with no indication of active exploitation, patch deployment, or debunking.

    01038511
    1.2K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    General

    🚨 CVE-2025-32463 - critical 🚨 Sudo - Local Privilege Escalation via chroot > Sudo before 1.9.17p1 allows local users to obtain root access by using /etc/nsswitch.... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-32463 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2025-32463, a critical local privilege escalation in older Sudo versions (<1.9.17p1) using /etc/nsswitch, but does not provide exploit code, active use evidence, or patch information.

    00002344
    905 followersView on X
  • IT Cat ✈️@itcaat
    General

    @gaxeliy @Wandrovik Также уязвимости Linux (я что вам какая то шутка ) CVE-2025-38561, CVE-2025-6018, CVE-2025-6019, CVE-2025-32463, CVE-2026-24061

    Post summary

    The text simply lists several Linux CVE identifiers without providing additional context, technical details, or actionable information.

    1001049
    1.5K followersView on X
  • enpi@enpits
    Patch

    @LundukeJournal https://nvd.nist.gov/vuln/detail/cve-2025-32463 Probably there for up to 10 years until a patch was released in jan 2025. Yet to this day, many system remained vulnerable. But posting CVEs with impressive names sure produces engagement : I myself got baited.

    Post summary

    The tweet references CVE-2025-32463 and notes that a patch was released in January 2025, yet many systems remain vulnerable.

    10001310
    27 followersView on X
  • Syn Marnotrawny 🇵🇱@th_prodigal_son
    Patch

    @ljachowicz . wszystko tu można wymyślić ale sam widzisz ilości stwierdzeń warunkowych, a ja mam na myśli jedynie fakt, żeby być w miarę precyzyjnym w naganianiu tej paniki… to lokalna klapa porównywalna w skutkach do CVE-2021-3156 albo CVE-2025-32462/CVE-2025-32463 i wystarczy zpatchować

    Post summary

    The comment highlights a vulnerability (referencing CVE‑2021‑3156 and CVE‑2025‑32462/32463) and stresses that simple patching will mitigate it.

    00001891
    1.8K followersView on X
  • Tanguy 🚲🐈‍⬛🧀🧆🇫🇷🇪🇺@Tanguy826021531
    General

    @lcfr_eth Not a single privilege escalation on Linux since 2010 ? Not even CVE-2025-32463 ?

    Post summary

    The tweet asks whether CVE‑2025‑32463 is a privilege‑escalation flaw on Linux but gives no technical or exploit information.

    00010928
    16 followersView on X
  • Linuxmaster.jp リナックスマスター.JP@Linuxmaster_JP
    Patch

    【結論】sudo脆弱性(CVE-2025-32463)は、まずアップデートが最優先です。 sudo 1.9.17p1より前が影響範囲とされていて、ローカルユーザーからroot権限に繋がる可能性があります(出典:NVD 2025/06/30)。 ※深刻度は評価元により表記が分かれます(CNA評価でCVSS 9.3、NVD側では7.8表記もあり)。 ■ まず確認するなら、これだけ(保存版) 1) sudo -V でバージョン確認 2) 修正版へ更新(RHEL系は dnf/yum、Debian系は apt) 3) 事前に仮想環境で試す(壊してもいい環境だと気が楽になります) ■ NG(これをやると危険です) ・ バージョン確認せずに放置する ・ 本番環境でいきなり更新する ・ 更新後の動作確認を省略する ポイントは「学ぶ順番」です。 先に安全な環境で手順を試す → それから本番に適用、これが最適なステップアップです。 安全な環境が作れる無料マニュアルのリンクは、次のリプに置いてあります。

    Post summary

    The post highlights CVE-2025-32463, provides technical details of the local privilege escalation risk, and focuses on the need for immediate patching via standard package managers.

    1000070
    117 followersView on X
  • 宮崎智広@ITエンジニア@miyazakitom
    Patch

    多くの人が勘違いしてるのは、sudo脆弱性を「自分には関係ない」と考えてる点です。 実際、Verizonの2025 DBIRでは「脆弱性の悪用」が初期侵入で使われる割合が前年比34%増えたと報告されています(出典:Verizon DBIR 2025/04/23)。 sudoにも複数の脆弱性(例:CVE-2025-32462 / CVE-2025-32463)が報告され、ローカル環境から権限昇格につながる可能性があるものもあります。 ※対象は「sudo 1.9.17p1 未満」(出典:NVD 2025/06/30 ほか) 難しく感じるかもしれませんが、やることは簡単です。 「壊しても誰にも迷惑が掛からない環境」で、手順通りに実行するだけです。 もし、試すならこれだけでOKです。 1) AlmaLinuxの仮想環境を立てる(壊してOK) 2) sudo -V でバージョン確認 3) 古いバージョンなら更新コマンドを実行(例:RHEL系は dnf update sudo) 手順通りにやるだけで、いつでも試せる環境が作れれば 本番サーバーを触る前に、「安全な場所で手を動かす経験」が積めます。それがあるかないかで、現場での対応速度がまるで違います。 そんな環境が作れる無料マニュアルのリンクは、次のリプに置いてあります。

    Post summary

    The post announces newly disclosed sudo CVEs that enable local privilege escalation and recommends updating sudo to mitigate the risk.

    1000047
    531 followersView on X
  • strikoder@Strikoder
    PoC

    New HackTheBox walkthrough: Expressway UDP enumeration → IPsec IKE aggressive mode → PSK cracking → CVE-2025-32463 sudo privilege escalation. VPN pentesting meets modern privesc. https://youtu.be/RsoQJJvo8Is #HackTheBox #VPN #IPsec https://t.co/EGVviOTnEE

    Post summary

    The post shares a video walkthrough demonstrating how CVE-2025-32463 can be leveraged for privilege escalation via IPsec IKE PSK cracking, serving as a proof‑of‑concept. There is no mention of active exploitation, patches, or debunking.

    00000178
    15 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux22.04--
OScanonicalubuntu_linux24.04--
OScanonicalubuntu_linux24.10--
OScanonicalubuntu_linux25.04--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSdebiandebian_linux13.0--
OSopensuseleap15.6--
OSredhatenterprise_linux10.0--
Appsudo_projectsudo---
Appsudo_projectsudo1.9.17--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_server_for_sap12--
OSsuselinux_enterprise_server_for_sap12--

Explore more