{"id":"AZL-98225","summary":"CVE-2026-82474 affecting package sudo 1.9.17-2","details":"Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.","modified":"2026-09-03T05:27:10Z","published":"2026-08-29T17:17:59Z","upstream":["CVE-2026-82474"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82474"}],"affected":[{"package":{"name":"sudo","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/sudo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.9.17-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98225.json"}}],"schema_version":"1.9.0"}