Sudo and the timezone that rewrites the clock: CVE-2026-96512
Sudoers time restrictions look like a clean control. A rule can allow a command only before a deadline or only after a start time, and administrators use that shape to bound maintenance windows and temporary access. CVE-2026-96512 shows what happens when the component that evaluates the clock reads the time from somewhere the user controls.
What the vulnerability is
Sudo decides whether a time-based sudoers rule applies by parsing its NOTBEFORE and NOTAFTER values and comparing them against the current time. In affected versions, that comparison runs in the environment the invoking user supplies. The TZ environment variable is part of that environment, and sudo runs as a setuid root binary that inherits it from the caller.
An attacker with a local account and a command allowed only inside a time window can set TZ so that sudo's notion of the current time lands inside the window. The reported example uses a value such as TZ=XXX24, which shifts the judged time far enough that an expired NOTAFTER rule looks valid again, or a future NOTBEFORE rule looks satisfied early. The judgement moves by roughly a day rather than by seconds.
The bug is in how parse_gentime() and the underlying mktime() handle that user-controlled input. The failure is not an arithmetic mistake in the comparison itself. The comparison is correct for the time it is handed, and the time it is handed is wrong.
What it does not do
CVE-2026-96512 does not bypass password authentication. It does not defeat PAM, and it does not grant privileges that the sudoers policy withholds. The requirement is a time-restricted rule plus a local account able to invoke the allowed command. Where those two conditions are absent, there is nothing to exploit.
That constraint matters when the finding is triaged. A host with no time-bounded sudoers entries is unaffected by this specific issue. A host that uses them to enforce a maintenance window is exactly the target, because the window is the control.
Affected versions and the state of the fix
Reported ranges cover sudo 1.8.20 through 1.9.17p2. The report is credited to Ermenson Junior on 2026-08-28. Todd Miller committed a patch to the main branch on 2026-08-29, and that patch had not reached a released 1.9.18 at the time of writing. Distributions will follow their own backport schedules, and the advisory history in each is the authoritative source for a given platform. Red Hat rated the issue high.
What to check and change
The practical sequence starts with the sudoers policy. Look for rules that carry NOTBEFORE or NOTAFTER, and record which commands they cover and which accounts can use them. Those rules are the population at risk.
Two mitigations are available before a patched package arrives. The first is to express the time boundaries as explicit UTC offsets rather than relying on a local or user-influenced interpretation of the timezone. The second is to remove the time restriction where it is decorative and keep it only where it is load-bearing, then compensate for the window with a control that does not depend on the caller's environment.
When the patched package is available, the update path is the ordinary one, with a follow-up check that the time-based rules still evaluate as intended after the change.
Why the bug class matters more than the bug
The interesting detail in CVE-2026-96512 is not the arithmetic. It is the direction the input traveled. Sudo runs with elevated privilege and, for this decision, accepted an environmental value from the unprivileged caller. The same pattern appears wherever a privileged component reads configuration, locale, timezone, path or proxy settings out of the environment of the process that invoked it.
That is the reason to treat the finding as a template as well as a ticket. Reviewing other setuid binaries and privileged services for the same dependency on inherited environment is cheap, and the review is more durable than any single patch.
References
- Freebuf report on CVE-2026-96512: https://www.freebuf.com/news/503342.html
- Cybersecurity News coverage: https://cybersecuritynews.com/sudo-security-vulnerability/
- Sudo project and advisories: https://www.sudo.ws/
Top comments (0)