An alert published on September 24, 2026 reports that the TZ variable can still alter NOTBEFORE/NOTAFTER checks in sudoers rules. The available excerpt does not state the full impact.
An oss-sec feed alert, published on September 24, 2026 and presented as an automatic translation, reports CVE-2026-96512, a sudo bug involving NOTBEFORE and NOTAFTER checks in sudoers rules. According to the text, the TZ variable set by the user invoking the program can still affect these checks.
The explanation says that when a rule’s timestamp does not end in Z, parse_gentime() uses mktime(), which consults TZ. An earlier fix covered localtime_r() but did not prevent the use of mktime(). The supplied excerpt ends before completing its description of the effect of an extreme offset, so it does not establish the full impact. Consult the original alert in the oss-sec archive and verify the version and technical details against official sudo and CVE sources.