СloudLinux Blog

CloudLinux OS 6 ELS: sudo package with the fix for the CVE-2021-23240 gradual rollout

Written by Inessa Atmachian | Jul 7, 2021 10:23:35 AM

A new updated sudo package with the fix for the CVE-2021-23240 within CloudLinux OS 6 ELS has been scheduled for gradual rollout from our production repository.

Rollout slot: 10
Rolled out to: 1%
ETA for 100% rollout: July 20

CHANGELOG

sudo-1.8.6p3-32.el6.cloudlinux.els

  • Fix symbolic link attack in SELinux-enabled sudoedit (CVE-2021-23240)

UPDATE COMMAND

yum update sudo*

IMMEDIATE UPDATE (VIA BYPASS)

yum update sudo* --enablerepo=cloudlinux-rollout-10-bypass