Update to address two moderate vulnerabilities

Bug #2130623 reported by Simon Johnsson
266
This bug affects 1 person
Affects Status Importance Assigned to Milestone
rust-sudo-rs (Ubuntu)
Fix Released
Undecided
Unassigned
Plucky
Confirmed
Undecided
Unassigned
Questing
Fix Released
Undecided
Unassigned

Bug Description

PPA with fix: https://launchpad.net/~bamf0/+archive/ubuntu/rust-sudo-rs-lp2130623/+packages
Repository with fix: https://code.launchpad.net/~bamf0/ubuntu/+source/cve-fixes/+git/cve-fixes/+ref/sudo-rs-sru-lp2130623-questing
---
Upstream will release a fix for two moderate vulnerabilities targeting Friday (Nov 7 2025).

The expected coordinated release of this fix is Monday (Nov 10 2025).

One of these vulnerabilities is CVE-2025-64170.

Course of action:
- The change suggested by upstream is to update the package (SRU)
- There are not any changes in dependencies with respect to version 0.2.8

Tags: patch
Simon Johnsson (bamf0)
summary: - Please Fix Bug
+ Update to address two moderate vulnerabilities
Revision history for this message
Simon Johnsson (bamf0) wrote (last edit ):

We have been in contact with Marc Schoolderman <email address hidden> from upstream.

Marc Deslauriers <email address hidden> from security has been notified.

description: updated
Simon Johnsson (bamf0)
description: updated
Simon Johnsson (bamf0)
description: updated
Simon Johnsson (bamf0)
description: updated
Revision history for this message
Simon Johnsson (bamf0) wrote :

The fixes have been released and I am preparing a security SRU.

Revision history for this message
Simon Johnsson (bamf0) wrote :

Here is the preliminary patch for GHSA-c978-wq47-pvvw. Awaiting build success before forwarding to security.

description: updated
Revision history for this message
Simon Johnsson (bamf0) wrote :

Here is the preliminary patch for GHSA-q428-6v73-fc4q. Awaiting build success before forwarding to security.

Revision history for this message
Wesley Hershberger (whershberger) wrote :

Hey Simon, thanks for hopping on this. Security uploads have a few special requirements for changelog entries and should target `questing-security` instead of `questing` [1].

lp-2130623-GHSA-q428-6v73-fc4q.patch looks good to me.

[1] https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Packaging

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I am preparing the questing security upload in the security team PPA now.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package rust-sudo-rs - 0.2.8-1ubuntu5.2

---------------
rust-sudo-rs (0.2.8-1ubuntu5.2) questing-security; urgency=high

  * SECURITY UPDATE: multiple security fixes (LP: #2130623)
    - debian/patches/lp-2130623-GHSA-q428-6v73-fc4q-*.patch
    - debian/patches/lp-2130623-GHSA-c978-wq47-pvvw-*.patch
    - CVE numbers pending

 -- Simon Johnsson <email address hidden> Mon, 10 Nov 2025 16:12:00 +0100

Changed in rust-sudo-rs (Ubuntu Questing):
status: New → Fix Released
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I am making this bug public since the two commits are now in the upstream repo and listed in the changes file.

information type: Private Security → Public Security
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "lp-2130623-GHSA-c978-wq47-pvvw.patch" seems to be a patch. If it isn't, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are a member of the ~ubuntu-reviewers, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issues please contact him.]

tags: added: patch
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

FYI, an update for these issues was published for Ubuntu 25.10 on Monday:

https://ubuntu.com/security/notices/USN-7867-1

Changed in rust-sudo-rs (Ubuntu):
status: New → Fix Released
Changed in rust-sudo-rs (Ubuntu Plucky):
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.