Red Hat Fixes Sudo Time-Window Authorization Bypass on RHEL 8–10

P1 — VALIDATE AND UPDATEHigh · 7.8 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat extended the CVE-2026-96512 sudo fix across RHEL 8, 9, and 10. Systems are specifically exposed when sudoers NOTBEFORE or NOTAFTER timestamps omit the trailing Z designator. Audit those rules, install the branch-specific fixed package, and validate authorization windows.

Audit Time-Restricted Sudoers Rules And Update RHEL 8–10

What to do now: Locate RHEL 8–10 systems using NOTBEFORE or NOTAFTER controls, preserve and review policy, install the advisory package for each branch, and test allowed and denied time windows.

Open the authoritative advisory

Last verified: 2026-10-05 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeRed Hat Enterprise Linux 8, 9, and 10 sudo packages
AdvisoryRHSA-2026:75580 / RHSA-2026:75579 / RHSA-2026:75571
CVECVE-2026-96512
Authoritative release date2026-10-05 03:17:18 UTC
Authority revision date2026-10-05 10:49:08 UTC
Affected versionsRHEL 8–10 sudo packages before their advisory-listed fixed builds where NOTBEFORE or NOTAFTER restrictions are used without an explicit UTC suffix.
Fixed versionsudo 1.9.5p2-2.el8_10 / 1.9.17p2-3.el9_8.3 / 1.9.17-10.p2.el10_2.7
CVSS base score7.8 (CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Red Hat extended the CVE-2026-96512 fix from RHEL 8 to supported RHEL 9 and RHEL 10 branches with branch-specific replacement packages.

What To Validate Now

  1. Inventory. Record RHEL release, sudo package, policy source, owner, and every local or centrally distributed sudoers rule using NOTBEFORE or NOTAFTER.
  2. Establish applicability. Confirm whether time-window controls omit an explicit trailing Z. The optional restriction is not enabled by default; do not infer applicability from sudo presence alone.
  3. Remediate. Install the advisory-listed sudo build for RHEL 8, 9, or 10. Red Hat documents adding a trailing Z to each affected timestamp as a temporary workaround.
  4. Validate. Verify the installed RPM, validate sudoers syntax, test before, inside, and after each controlled window, and confirm central policy distribution remains intact.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Back up sudoers and retain a separate privileged session before changing authorization policy. A malformed rule can lock out administrators; the UTC suffix is a temporary control, not a substitute for updating.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.