[Bug 2143042] Re: exec_mailer: Set group as well as uid when running the mailer

Launchpad Bug Tracker 2143042 at bugs.launchpad.net
Thu Mar 12 20:01:00 UTC 2026


This bug was fixed in the package sudo - 1.9.15p5-3ubuntu5.24.04.2

---------------
sudo (1.9.15p5-3ubuntu5.24.04.2) noble-security; urgency=medium

  * SECURITY UPDATE: exec_mailer gid issue (LP: #2143042)
    - debian/patches/lp2143042.patch: set group as well as uid when running
      the mailer and make a setuid(), setgid() or setgroups() failure fatal
      in include/sudo_eventlog.h, lib/eventlog/eventlog.c,
      lib/eventlog/eventlog_conf.c, plugins/sudoers/logging.c,
      plugins/sudoers/policy.c.
    - No CVE number

 -- Marc Deslauriers <marc.deslauriers at ubuntu.com>  Mon, 02 Mar 2026
07:56:19 -0500

** Changed in: sudo (Ubuntu)
       Status: New => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to sudo in Ubuntu.
https://bugs.launchpad.net/bugs/2143042

Title:
  exec_mailer: Set group as well as uid when running the mailer

Status in sudo package in Ubuntu:
  Fix Released

Bug description:
  From upstream commit:

  exec_mailer: Set group as well as uid when running the mailer
  Also make a setuid(), setgid() or setgroups() failure fatal.

  This issue has no CVE.

  https://github.com/sudo-project/sudo/commit/3e474c2

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042/+subscriptions




More information about the foundations-bugs mailing list