Skip to content
Rota Nacional

Cyber ·

USN-8895-1: Sudo flaw lets local users bypass time restrictions through the TZ variable

Ubuntu Security notice describes a Sudo flaw where sudoers rules using NOTBEFORE or NOTAFTER with timestamps lacking a trailing timezone indicator could let a local attacker run commands outside the allowed window.

Notice USN-8895-1, published on October 7, 2026 in the Ubuntu Security feed, describes a vulnerability in Sudo. According to the text received, Sudo did not correctly handle time-based access restrictions when sudoers rules used the NOTBEFORE or NOTAFTER directives with timestamps lacking a timezone indicator at the end. A local attacker could possibly exploit this to run commands outside the intended time window by manipulating the TZ environment variable. The excerpt available does not list affected versions or the fixed version; those details should be checked in the original notice. For readers, the relevance lies in combining time-based sudoers rules with local access: a time restriction that seems guaranteed may not hold if the environment allows TZ to be changed. The responsible approach is to check whether the organization uses Sudo with these directives, apply the vendor package update, and record the verification. Rota Nacional does not patch operating system packages or replace server updates.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free