FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

security/sudo-rs -- sudoedit could circumvent /etc/sudoers restrictions

Affected packages
0.2.8 <= sudo-rs < 0.2.15
0.2.8 <= sudo-rs-coexist < 0.2.15

Details

VuXML ID c0acdbac-a524-11f1-8039-589cfc103809
Discovery 2026-08-31
Entry 2026-08-31

Trifecta Tech Foundation reports:

Users that are explicitly permitted to edit only specific files using sudoedit, are still able to place files in arbitrary directories.

This only affects systems where sudoedit is used to give very fine-grained edit permissions, which is not the default configuration. For users that have full sudoedit permission or no sudoedit permission at all, no escalation is enabled by this bug.

A user that is allowed to place files in an arbitrary directory can (by placing a file in /etc/sudoers.d) obviously fully escalate their privileges.

References

URL https://github.com/trifectatechfoundation/sudo-rs/releases/tag/v0.2.15
URL https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-f42v-x7gq-phc8