[CLSA-2026:1788786535] Fix CVE(s): CVE-2023-42465
Type:
security
Severity:
Important
Release date:
2026-09-07 13:09:05 UTC
Description:
* SECURITY UPDATE: harden sudo against ROWHAMMER bit-flip attacks - debian/patches/CVE-2023-42465.patch: use ROWHAMMER-resistant values for ALLOW/DENY and the AUTH_* codes and explicitly test for expected values instead of negated tests in the parser and authentication code - CVE-2023-42465
CVEs fixed:
Updated packages:
  • sudo_1.9.5p2-3+deb11u4+tuxcare.els1_amd64.deb
    sha:734672c78afb03ba9740244da9cc47935beb5802
  • sudo-ldap_1.9.5p2-3+deb11u4+tuxcare.els1_amd64.deb
    sha:0f5fd763137956fbce053ba1240b7fc95e707945
  • sudo_1.9.5p2-3+deb11u4+tuxcare.els1_arm64.deb
    sha:a754225b3e8731eb590f7022698c41e19a60450e
  • sudo-ldap_1.9.5p2-3+deb11u4+tuxcare.els1_arm64.deb
    sha:1e5d2e5d2c439201d0ed9f112c5c11d9c6be858c
  • sudo_1.9.5p2-3+deb11u4+tuxcare.els1_armel.deb
    sha:bff28e6159d1a9baa84a2864e2bc12a009dfc72b
  • sudo-ldap_1.9.5p2-3+deb11u4+tuxcare.els1_armel.deb
    sha:3f75c1aa9448addf3fa3fb137bbc2bb71196214a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.