sudo: Memory Manipulation A vulnerability has been discovered in sudo which can lead to execution manipulation through rowhammer-style memory manipulation. sudo 2024-01-24 2024-01-24 920510 remote 1.9.15_p2 1.9.15_p2

sudo allows a system administrator to give users the ability to run commands as other users.

Multiple vulnerabilities have been discovered in sudo. Please review the CVE identifiers referenced below for details.

Stack/register variables can be flipped via fault injection, affecting execution flow in security-sensitive code.

There is no known workaround at this time.

All sudo users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-admin/sudo-1.9.15_p2"
CVE-2023-42465 graaff ajak