rpm package
almalinux/sssd-passkey
pkg:rpm/almalinux/sssd-passkey
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-14476 | Hig | 8.0 | < 2.12.0-3.el10_2.1 | 2.12.0-3.el10_2.1 | Jul 7, 2026 | A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. | |
| CVE-2026-14474 | Hig | 8.8 | < 2.12.0-3.el10_2.1 | 2.12.0-3.el10_2.1 | Jul 7, 2026 | A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting r | |
| CVE-2025-11561 | Hig | 8.8 | < 2.9.7-4.el9_7.1 | 2.9.7-4.el9_7.1 | Oct 9, 2025 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. Th | |
| CVE-2023-3758 | Hig | 7.1 | < 2.9.4-6.el9_4 | 2.9.4-6.el9_4 | Apr 18, 2024 | A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. |
- affected < 2.12.0-3.el10_2.1fixed 2.12.0-3.el10_2.1
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root.
- affected < 2.12.0-3.el10_2.1fixed 2.12.0-3.el10_2.1
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting r
- affected < 2.9.7-4.el9_7.1fixed 2.9.7-4.el9_7.1
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. Th
- affected < 2.9.4-6.el9_4fixed 2.9.4-6.el9_4
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.