>>106134178
Yes, CVE-2023-42465

Debian tracker
https://security-tracker.debian.org/tracker/source-package/sudo

Red Hat bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2023-42465

RHEL errata (tracker)
https://access.redhat.com/errata/RHSA-2024:0811

Canonical usually patch it fast this specific CVE didn't load because of API error
https://ubuntu.com/security/CVE-2023-42465

So to be fair, Debian does not like to have close ties with enterprise for this sort of stuff and waits until the community patches it, the disadvantage is if you don't rely on enterprise or vendors you will have slower patching. There are some other examples, I did have an issue with openssh and openssl during a security audit.