Home › Linux root and sudo security › Step 8

Lesson 8: Sudoers environment security

Step 8 of 13 in Linux root and sudo security · video 7:08

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Environment variables are a quiet route to privilege escalation, and this lesson covers the sudoers settings that close it. It lists the existing environment defaults with sudo grep -E "Defaults.*env" /etc/sudoers, then writes /etc/sudoers.d/env-security for a test account, envuser. env_reset discards the caller's environment and builds a clean one, so a PATH pointing at /tmp or a planted variable does not reach the root process. secure_path fixes the directories searched for commands. env_keep lets only LANG, LC_* and TZ through, since they affect language, formats and time zone rather than which code runs, and env_delete explicitly removes LD_PRELOAD and LD_LIBRARY_PATH, the dynamic linker variables that can load a hostile library into a root process. The account may run env, echo and whoami without a password, and visudo catches a Defaults line that was split across two lines before the file is saved.

Good to know: allowing /usr/bin/env as root without a password gives full root, because sudo env /bin/bash starts a root shell; lesson 9 removes it again. env_reset is already on in RHEL's default sudoers, and sudo removes LD_ variables itself, so these lines are an extra layer.

Check yourself

Answer in your head first, then open each question to see the answer.

1. An attacker runs export PATH=/tmp/malicious:$PATH and then a sudo command. How do env_reset and secure_path stop a fake ls in /tmp/malicious from running as root?

env_reset throws away the caller's environment, and secure_path sets the PATH used by sudo to a fixed list of system directories. The planted binary is not on that path, so the real system command runs instead.

2. Why is it considered safe to keep LANG, LC_* and TZ with env_keep?

They only control language, date and number formats and the time zone, so they do not change which code runs. Keeping them avoids garbled output and wrong times in logs without opening an attack route.

3. What do LD_PRELOAD and LD_LIBRARY_PATH do, and why does the lesson remove them with env_delete?

LD_PRELOAD makes the dynamic linker load a chosen shared library first, and LD_LIBRARY_PATH changes where libraries are searched. Either could run an attacker's code inside a root process, so they are removed even if other variables are allowed through.

4. visudo reports an error after the secure_path value was split across two lines. How do you fix it?

Put the whole Defaults:envuser secure_path=... entry on one line (or end the first line with a backslash). sudoers reads each new line as a new entry, so the orphaned second half is a syntax error.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 7: Advanced sudoers configuration: logging, aliases and denialsNext: Lesson 9: Testing sudo security with environment variables →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.