News

USN-8895-1: sudo flaw bypasses NOTBEFORE/NOTAFTER time restrictions

A bug in sudo lets a local user bypass sudoers time restrictions by manipulating the TZ variable. Patches available for 22.04, 24.04 and 26.04 LTS.

UptimeMag editorial team · 7 October 2026 · 1 min read

USN-8895-1: falla in sudo, bypass delle restrizioni orarie NOTBEFORE/NOTAFTER

Ubuntu has published security notice USN-8895-1, dated 7 October 2026, for a vulnerability in sudo affecting anyone using time-based restrictions in sudoers rules. This matters for those managing Ubuntu servers with access policies limited to specific time windows: a local user can bypass them.

The problem

According to the advisory, sudo did not correctly handle time-based access restrictions when sudoers rules used the NOTBEFORE or NOTAFTER directives with timestamps lacking a trailing timezone indicator. A local attacker could exploit this bug to run commands outside the intended time window by manipulating the TZ environment variable.

The vulnerability is tracked as CVE-2026-96512.

Affected packages and fixed versions

The package affected is sudo (and sudo-ldap where present). The versions that fix the issue, by release:

Ubuntu release Package Fixed version
26.04 LTS (resolute) sudo 1.9.17p2-1ubuntu3.2
24.04 LTS (noble) sudo 1.9.15p5-3ubuntu5.24.04.4
24.04 LTS (noble) sudo-ldap 1.9.15p5-3ubuntu5.24.04.4
22.04 LTS (jammy) sudo 1.9.9-1ubuntu2.7
22.04 LTS (jammy) sudo-ldap 1.9.9-1ubuntu2.7

What to do

A standard system update (apt update && apt upgrade) applies the fixed versions. Anyone using sudoers rules with NOTBEFORE or NOTAFTER should verify after updating that time windows are being enforced as expected, especially if the timestamps in use do not include an explicit timezone.

Ubuntu notes that Ubuntu Pro provides ten years of security coverage for over 25,000 packages in the Main and Universe repositories, free for up to five machines.

Source: official USN-8895-1 advisory on ubuntu.com.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.