Critical sudo flaw (CVE‑2026‑96512) lets local users sidestep time‑based sudo limits
A newly disclosed vulnerability identified as CVE‑2026‑96512 has been classified as high severity because it enables an unprivileged, locally‑authenticated Linux user to override time‑based restrictions defined in a system's sudoers file. The flaw resides in the way the sudo program processes the TZ environment variable, allowing the attacker to manipulate the clock used for authorisation checks.
sudo is a cornerstone of Unix‑like operating systems, granting users temporary administrative privileges after they authenticate. Administrators often employ time‑based rules in the sudoers configuration to limit when certain commands may be executed, for example restricting privileged actions to business hours. Such controls are a common defence against misuse and are relied upon in environments ranging from personal laptops to large data centres.
The vulnerability emerges when sudo reads the TZ variable supplied by the invoking user. By providing a crafted timezone string, an attacker can cause sudo to calculate a different current time than the system clock reflects. Because the time‑based checks compare the computed time against the policy, the altered value can make a restricted command appear to fall within an allowed window, effectively bypassing the intended limitation.
In practice, the exploit requires only local access and does not need elevated privileges to set the TZ variable. Once the manipulated time is accepted, the user can execute commands that would otherwise be blocked, potentially obtaining root access if the sudo policy grants full privileges during the falsified interval. The attack surface is limited to systems where sudo is configured with time constraints and where the environment variable is not explicitly sanitized.
The flaw was first reported to the public by the security research collective GBHackers. Since the announcement, the sudo development team has acknowledged the issue and is working on a patch. Distributions that bundle sudo have been urged to monitor upstream updates and to incorporate the fix as soon as it becomes available.
Administrators are advised to apply the forthcoming patch promptly and to consider interim mitigations such as removing TZ from the list of permitted environment variables (env_keep) or enforcing stricter SELinux/AppArmor policies that limit the ability of unprivileged users to modify environment settings. Regularly reviewing sudoers configurations for unnecessary time‑based rules can also reduce the impact of this vulnerability. Prompt remediation will help maintain the integrity of privilege‑escalation controls that many Linux deployments depend on.
Comments (0)
Be the first to comment.
Join the discussion