CVE detail
CVE-2026-35535
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
36 source links · newest first
- Siemens SINEC OSCISA Alerts
Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight soc
governmentwww.cisa.govJul 7, 2026, 12:00 PM - Debian 13.5 point release lands with security fixes, bug patchesHelp Net Security
Debian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Fresh installer images carrying the same fixes will follow at the regular download locations. Sysadmins running trixie do not need to reinstall. Existing media remain valid, and machines … More →
newswww.helpnetsecurity.comMay 17, 2026, 10:03 PM - CVE-2026-35535Microsoft MSRC
Information published.
vendormsrc.microsoft.comApr 11, 2026, 8:40 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35535.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 3, 2026, 3:16 AM - https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comApr 3, 2026, 3:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2454714bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/security/cve/CVE-2026-35535access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:34098access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:30088access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:28887access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:23233access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:21695access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:21690access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:21656access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:21275access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:20087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:20040access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:19220access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:19067access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:14437access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:14228access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13896access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13895access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13892access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13891access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13889access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13888access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:13731access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:12310access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:11521access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM - https://access.redhat.com/errata/RHSA-2026:10758access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 3, 2026, 3:16 AM No excerpt available.
Vendor Advisorylists.debian.orgApr 3, 2026, 3:16 AM- https://www.qualys.com/2026/03/10/crack-armor.txtwww.qualys.com
No excerpt available.
Third Party Advisorywww.qualys.comApr 3, 2026, 3:16 AM No excerpt available.
Exploitgithub.comApr 3, 2026, 3:16 AM- https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042bugs.launchpad.net
No excerpt available.
Exploitbugs.launchpad.netApr 3, 2026, 3:16 AM - https://bugs.debian.org/1130593bugs.debian.org
No excerpt available.
Issue Trackingbugs.debian.orgApr 3, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-50302CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in vario…
- CVE-2026-15271CVSS 7.7 · High
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown funct…
- CVE-2026-15270CVSS 6.8 · Medium
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web…
- CVE-2026-11620CVSS 5.5 · Medium
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results…
- CVE-2026-11555CVSS 2.9 · Low
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipula…
- CVE-2026-11554CVSS 2.1 · Low
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation cause…