All findings

zeropath-sudo-exec-mailer-crackarmor high

ZeroPath AI Security Engineer credited on sudo exec_mailer fix

The sudo project credited the ZeroPath AI Security Engineer for an exec_mailer fix that made privilege-drop failures fatal and dropped group privileges; Qualys later documented the same sudo behavior as part of its CrackArmor AppArmor + Sudo + Postfix root chain.

Bug class
Incomplete privilege drop in sudo mailer execution
Affected codebase
sudo
Credited system
ZeroPath AI SAST
Disclosed
November 8, 2025
Attribution
Direct source attribution
Severity
high
Source status: The upstream sudo commit directly credits the ZeroPath AI Security Engineer. Qualys later documented the same exec_mailer behavior in the CrackArmor user-space LPE chain, and ZeroPath's follow-up post maps the CrackArmor-relevant issue back to the same sudo commit. This is indexed as a no-CVE sudo finding, not as one of Qualys's AppArmor CVEs.

Summary

The sudo project fixed an exec_mailer privilege-dropping bug in commit 3e474c2. The patch sets the mailer’s group as well as its UID, adds setgroups() handling, and makes failed setuid(), setgid(), or setgroups() calls fatal.

Qualys later documented the same behavior in its CrackArmor technical report. In the user-space chain, an attacker who could load an AppArmor profile that denied CAP_SETUID to sudo could prevent sudo from dropping root before it invoked Postfix’s sendmail with attacker-controlled MAIL_CONFIG.

This entry is therefore scoped to the sudo issue. It does not attribute the CrackArmor AppArmor vulnerabilities to ZeroPath.

Attribution

This is direct attribution. The upstream sudo commit says the issue was found by the ZeroPath AI Security Engineer, and Qualys’s technical report repeats that credit when noting that the fail-open sudo behavior had already been independently discovered, reported, and fixed.

Bugflation keeps the system profile under “ZeroPath AI SAST” because that is the product-level name used elsewhere in the ZeroPath public materials, while preserving the exact “ZeroPath AI Security Engineer” wording in this finding.

Why it matters

This is stronger public evidence than a self-reported vendor blog alone. The AI attribution appears in an upstream sudo commit, and Qualys independently connected the same bug class to a practical local-root chain. The boundary is also important: the AppArmor CVEs remain Qualys findings, while the sudo exec_mailer fix is a ZeroPath-credited supporting issue in that chain.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.