• News/
  • https://www.theregister.com/2025/11/13/ubuntu_rust_sudo_hole/

Ubuntu 25.10's Rusty sudo holes quickly welded shut

The Register
·
Liam Proven
·
Published Nov 13, 2025
·
Updated

Two vulnerabilities in Ubuntu 25.10's new "sudo-rs" command have been found, disclosed, and fixed in short order. On Monday, Ubuntu security notice USN-7867-1 revealed two security holes in the new Rusty sudo command, whose arrival in version 25.10 The Register described back in May. The sudo is a separate project from the other new Rust component in Questing Quokka, the Rust replacements for the GNU coreutils. True, security vulnerabilities are a bad thing for a core tool whose purpose is authentication and elevating permissions, but the holes are fairly minor and would be hard to exploit. The Reg FOSS desk encountered sudo in the first public beta of Mac OS X, way back in 2000, but the classic C version is a venerable tool. It's so old that precise initial dates are lost to time, but the project's own history says it dates back to 1980. (The project's logo is much younger than the code – it's a reference to a 2006 XKCD comic.) Ubuntu has included the sudo command – and discouraged use of the all-powerful root account – since its very first release, 4.10 "Warty Warthog." The new sudo-rs implementation is a total rewrite, and project lead Marc Schoolderman of the Trifecta Tech Foundation delivered a talk about it at last month's Ubuntu Summit, titled "Sudo-rs and beyond." This vulture attended that talk and spoke to Schoolderman afterwards, so we contacted him. Here's what happened from the horse's mouth: We've fixed two issues which for convenience I'll call the "password ti...

Read full article

Affected Software

1 affected component
Ubuntu sudo-rs=25.10
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are reported in the Ubuntu 25.10 release?

Two security vulnerabilities were found in the new 'sudo-rs' command of Ubuntu 25.10.

2

How quickly were the vulnerabilities in Ubuntu 25.10 addressed?

The vulnerabilities were disclosed and fixed in a short amount of time following their discovery.

3

What specific version of the Ubuntu software is affected by the vulnerabilities?

The vulnerabilities affect the 'sudo-rs' command in Ubuntu version 25.10.

4

What is the significance of the 'sudo-rs' command in Ubuntu?

The 'sudo-rs' command is a new implementation of the traditional 'sudo' command introduced in Ubuntu 25.10.

5

What action should users take regarding the vulnerabilities in Ubuntu 25.10?

Users should ensure their systems are updated to incorporate the latest security fixes for the 'sudo-rs' command.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203