Skip to finding
interesting · Privilege — Ubuntu

A narrow sudoedit grant on Ubuntu 26.04 can be turned into arbitrary privileged file placement.

Affects

sudo-rs, the Rust sudo and su implementation shipped by Ubuntu 26.04 LTS.

Ubuntu describes a time-of-check/time-of-use race in sudo-rs sudoedit path handling: a local user granted the right to edit specific named files can win the race and have files placed in directories of their choosing instead. The point of a fine-grained sudoedit rule is that the list of files is the boundary, and this removes the boundary while leaving the rule looking intact.

Detail and 1 source

Ubuntu says the issue only affects systems configured with fine-grained sudoedit file editing permissions, which is not the default configuration.

Chain to watch
Local account holds sudoedit permission for specific named files→↓Attacker wins the sudo-rs path-handling race during the edit→↓sudo-rs writes the attacker-controlled file into a directory outside the grant→↓A placed file is picked up and run by an administrator or a service→↓The exact file target that converts arbitrary privileged placement into reliable root code execution on stock Ubuntu 26.04 is not documented in the notice.
Unverified chainRead the Launchpad bug or the patch and test common targets against a configured sudoedit rule — writable root-owned configuration paths, or service drop-ins.

The step nobody has written down is which target turns arbitrary privileged placement into reliable root execution on a stock 26.04 host — the notice does not say, and until someone does, this is a boundary failure rather than a demonstrated escalation.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 1, 2026