[#388680] p11 EPERM sudo.git=1.9.16p2-alt3

Girar awaiter (sin) girar-builder at altlinux.org
Tue Jul 1 22:26:11 MSK 2025


https://git.altlinux.org/tasks/388680/logs/events.1.1.log
https://packages.altlinux.org/tasks/388680

subtask  name  aarch64  i586  x86_64
   #100  sudo     2:11  1:28    1:22

2025-Jul-01 19:18:10 :: task #388680 for p11 started by sin:
2025-Jul-01 19:18:10 :: message: security_release
#100 build 1.9.16p2-alt3 from /gears/s/sudo.git fetched at 2025-Jul-01 18:24:56 from sisyphus
2025-Jul-01 19:18:12 :: [i586] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:18:12 :: [x86_64] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:18:12 :: [aarch64] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:19:34 :: [x86_64] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:19:40 :: [i586] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:20:23 :: [aarch64] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:20:44 :: #100: sudo.git 1.9.16p2-alt3: build check OK
2025-Jul-01 19:20:46 :: build check OK
2025-Jul-01 19:20:52 :: noarch check OK
2025-Jul-01 19:20:54 :: plan: src +1 -1 =19695, aarch64 +6 -6 =34708, i586 +6 -6 =33805, noarch +1 -1 =20810, x86_64 +6 -6 =35474
#100 sudo 1.9.16p2-alt2 -> 1:1.9.16p2-alt3
 Tue Jul 01 2025 Evgeny Sinelnikov <sin at altlinux> 1:1.9.16p2-alt3
 - Security release (fixes: CVE-2025-32462, CVE-2025-32463) (closes: 55007):
  + Sudo's -h (--host) option could be specified when running a command or
    editing a file. This could enable a local privilege escalation attack if the
    sudoers file allows the user to run commands on a different host.
    For more information, see Local Privilege Escalation via host option:
    https://www.sudo.ws/security/advisories/host_any/
  + An attacker can leverage sudo's -R (--chroot) option to run arbitrary
    commands as root, even if they are not listed in the sudoers file. The chroot
    support has been deprecated an will be removed entirely in a future release.
 [...]
2025-Jul-01 19:20:54 :: sudo: closes bugs: 55007
2025-Jul-01 19:20:54 :: sudo: fixes vulnerabilities: CVE-2025-32462 CVE-2025-32463
2025-Jul-01 19:21:35 :: patched apt indices
2025-Jul-01 19:21:44 :: created next repo
2025-Jul-01 19:21:54 :: duplicate provides check OK
2025-Jul-01 19:22:32 :: dependencies check OK
2025-Jul-01 19:23:02 :: [x86_64 i586 aarch64] ELF symbols check OK
2025-Jul-01 19:23:16 :: [i586] #100 sudo: install check OK
2025-Jul-01 19:23:16 :: [x86_64] #100 sudo: install check OK
2025-Jul-01 19:23:23 :: [i586] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:24 :: [x86_64] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:26 :: [aarch64] #100 sudo: install check OK
2025-Jul-01 19:23:30 :: [i586] #100 sudo-devel: install check OK
2025-Jul-01 19:23:30 :: [x86_64] #100 sudo-devel: install check OK
2025-Jul-01 19:23:36 :: [i586] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:23:37 :: [x86_64] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:23:38 :: [aarch64] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:44 :: [i586] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:23:44 :: [x86_64] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:23:49 :: [aarch64] #100 sudo-devel: install check OK
2025-Jul-01 19:23:52 :: [i586] #100 sudo-python: install check OK
2025-Jul-01 19:23:52 :: [x86_64] #100 sudo-python: install check OK
2025-Jul-01 19:24:00 :: [aarch64] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:24:02 :: [i586] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:02 :: [x86_64] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:12 :: [aarch64] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:24:25 :: [aarch64] #100 sudo-python: install check OK
2025-Jul-01 19:24:40 :: [aarch64] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:42 :: [x86_64-i586] plan: #2 +2 -2 =11690
2025-Jul-01 19:25:02 :: [x86_64-i586] arepo build OK
2025-Jul-01 19:25:21 :: [x86_64-i586] generated apt indices
2025-Jul-01 19:25:23 :: [x86_64-i586] created next repo
2025-Jul-01 19:25:36 :: [x86_64-i586] dependencies check OK
2025-Jul-01 19:25:38 :: gears inheritance check OK
2025-Jul-01 19:25:38 :: srpm inheritance check OK
girar-check-perms: access to sudo DENIED for sin: project `sudo' is not listed in the acl file for repository `p11', and the policy for such projects in `p11' is to deny
check-subtask-perms: #100: sudo: needs approvals from members of @maint and @tester groups
2025-Jul-01 19:25:41 :: acl check FAILED
2025-Jul-01 19:26:01 :: created contents_index files
2025-Jul-01 19:26:08 :: created hash files: aarch64 i586 noarch src x86_64-i586 x86_64
2025-Jul-01 19:26:11 :: task #388680 for p11 EPERM


More information about the Girar-builder-p11 mailing list