>>106134178
Yes, CVE-2023-42465
Debian tracker
https://security-tracker.debian.org/tracker/source-package/sudo
Red Hat bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2023-42465
RHEL errata (tracker)
https://access.redhat.com/errata/RHSA-2024:0811
Canonical usually patch it fast this specific CVE didn't load because of API error
https://ubuntu.com/security/CVE-2023-42465
So to be fair, Debian does not like to have close ties with enterprise for this sort of stuff and waits until the community patches it, the disadvantage is if you don't rely on enterprise or vendors you will have slower patching. There are some other examples, I did have an issue with openssh and openssl during a security audit.