Summary
The sudo project fixed an exec_mailer privilege-dropping bug in commit
3e474c2. The patch sets the mailer’s group as well as its UID, adds
setgroups() handling, and makes failed setuid(), setgid(), or
setgroups() calls fatal.
Qualys later documented the same behavior in its CrackArmor technical report.
In the user-space chain, an attacker who could load an AppArmor profile that
denied CAP_SETUID to sudo could prevent sudo from dropping root before it
invoked Postfix’s sendmail with attacker-controlled MAIL_CONFIG.
This entry is therefore scoped to the sudo issue. It does not attribute the CrackArmor AppArmor vulnerabilities to ZeroPath.
Attribution
This is direct attribution. The upstream sudo commit says the issue was found by the ZeroPath AI Security Engineer, and Qualys’s technical report repeats that credit when noting that the fail-open sudo behavior had already been independently discovered, reported, and fixed.
Bugflation keeps the system profile under “ZeroPath AI SAST” because that is the product-level name used elsewhere in the ZeroPath public materials, while preserving the exact “ZeroPath AI Security Engineer” wording in this finding.
Why it matters
This is stronger public evidence than a self-reported vendor blog alone. The
AI attribution appears in an upstream sudo commit, and Qualys independently
connected the same bug class to a practical local-root chain. The boundary is
also important: the AppArmor CVEs remain Qualys findings, while the sudo
exec_mailer fix is a ZeroPath-credited supporting issue in that chain.
References
- sudo commit 3e474c2: exec_mailer group and uid handling
- Qualys technical report: CrackArmor
- ZeroPath: 36 Sudo bug fixes reduce CrackArmor's impact
- Qualys: CrackArmor critical AppArmor flaws
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.