Two vulnerabilities in Ubuntu 25.10's new "sudo-rs" command have been found, disclosed, and fixed in short order. On Monday, Ubuntu security notice USN-7867-1 revealed two security holes in the new Rusty sudo command, whose arrival in version 25.10 The Register described back in May. The sudo is a separate project from the other new Rust component in Questing Quokka, the Rust replacements for the GNU coreutils. True, security vulnerabilities are a bad thing for a core tool whose purpose is authentication and elevating permissions, but the holes are fairly minor and would be hard to exploit. The Reg FOSS desk encountered sudo in the first public beta of Mac OS X, way back in 2000, but the classic C version is a venerable tool. It's so old that precise initial dates are lost to time, but the project's own history says it dates back to 1980. (The project's logo is much younger than the code – it's a reference to a 2006 XKCD comic.) Ubuntu has included the sudo command – and discouraged use of the all-powerful root account – since its very first release, 4.10 "Warty Warthog." The new sudo-rs implementation is a total rewrite, and project lead Marc Schoolderman of the Trifecta Tech Foundation delivered a talk about it at last month's Ubuntu Summit, titled "Sudo-rs and beyond." This vulture attended that talk and spoke to Schoolderman afterwards, so we contacted him. Here's what happened from the horse's mouth: We've fixed two issues which for convenience I'll call the "password ti...
Ubuntu 25.10's Rusty sudo holes quickly welded shut
The Register
·Liam Proven
·Published Nov 13, 2025
·Updated
Affected Software
1 affected component
Ubuntu sudo-rs=25.10
Frequently Asked Questions
1
What vulnerabilities are reported in the Ubuntu 25.10 release?
Two security vulnerabilities were found in the new 'sudo-rs' command of Ubuntu 25.10.
2
How quickly were the vulnerabilities in Ubuntu 25.10 addressed?
The vulnerabilities were disclosed and fixed in a short amount of time following their discovery.
3
What specific version of the Ubuntu software is affected by the vulnerabilities?
The vulnerabilities affect the 'sudo-rs' command in Ubuntu version 25.10.
4
What is the significance of the 'sudo-rs' command in Ubuntu?
The 'sudo-rs' command is a new implementation of the traditional 'sudo' command introduced in Ubuntu 25.10.
5
What action should users take regarding the vulnerabilities in Ubuntu 25.10?
Users should ensure their systems are updated to incorporate the latest security fixes for the 'sudo-rs' command.