Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  CVE-2025-32463 Vulnerability in sudo

    Posted 18 days ago

    Hey OSS-Team,

    I would like to request the recommended method to remediate the sudo vulnerability on AIX, along with official references to confirm to my customer that the issue can be fully resolved.

    Thanks,

    Sarawut



    ------------------------------
    Sarawuth Mammoon
    ------------------------------


  • 2.  RE: CVE-2025-32463 Vulnerability in sudo

    Posted 17 days ago
    Edited by RESHMA KUMAR 17 days ago

    Hi Sarawuth,

    The latest version of sudo available in AIX Toolbox is 1.9.17p2. One can update to this version to fix this CVE.

    Please refer https://www.sudo.ws/security/advisories/chroot_bug/ for more details.

    Thanks!



    ------------------------------
    RESHMA KUMAR
    ------------------------------



  • 3.  RE: CVE-2025-32463 Vulnerability in sudo

    Posted 15 days ago

    Hi Reshma,

    Thank you for the information and the reference link.

    I would like to confirm one more point:
    My AIX system is currently running sudo version 1.8.8.
    According to the information in the link you provided, the affected versions are 1.9.14 through 1.9.17.

    Does this mean that version 1.8.8 is not impacted by CVE-2025-32463, and therefore does not require an update for this specific vulnerability?

    Thank,

    Sarawuth



    ------------------------------
    Sarawuth Mammoon
    ------------------------------



  • 4.  RE: CVE-2025-32463 Vulnerability in sudo

    Posted 15 days ago

    Hi Sarawuth,
    sudo 1.8.8 is not affected by CVE-2025-32463. However, it is good to update as this version is quite old. 



    ------------------------------
    RESHMA KUMAR
    ------------------------------



  • 5.  RE: CVE-2025-32463 Vulnerability in sudo

    Posted 10 days ago

    Hi Reshma,

    Thank you for the clarification.

    I have proceeded with the recommended update as suggested to address the issue.

    Thank,

    Sarawuth



    ------------------------------
    Sarawuth Mammoon
    ------------------------------