{"id":"USN-8708-1","summary":"rust-sudo-rs vulnerability","details":"It was discovered that sudo-rs incorrectly handled time-of-check vs time-\nof-use conditions in sudoedit. A local attacker with permission to edit\nspecific files using sudoedit could use this issue to place files in\narbitrary directories, and possibly escalate their privileges. This issue\nonly affected systems configured to grant fine-grained sudoedit file\nediting permissions, which is not the default configuration.","modified":"2026-09-01T21:00:04.433322156Z","published":"2026-09-01T12:58:08Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8708-1"},{"type":"REPORT","url":"https://bugs.launchpad.net/bugs/2165142"}],"affected":[{"package":{"name":"rust-sudo-rs","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/rust-sudo-rs?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.13-0ubuntu1.2"}]}],"versions":["0.2.8-1ubuntu5","0.2.8-1ubuntu5.1","0.2.10-1ubuntu1","0.2.10-1ubuntu2","0.2.12-0ubuntu1","0.2.12-0ubuntu3","0.2.13-0ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"0.2.13-0ubuntu1.2","binary_name":"sudo-rs"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8708-1.json","cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[]}}}],"schema_version":"1.9.0"}