Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:41937: Important: sssd security update

This security update addresses two high-severity vulnerabilities in the System Security Services Daemon (SSSD): CVE-2026-14474 (CVSS 8.8), a privilege escalation flaw where the sudo LDAP provider searches the entire directory tree for sudoRole objects, and CVE-2026-14476 (CVSS 8.0), a GPO cache path traversal via unsanitized `gPCFileSysPath` that allows Kerberos authentication bypass. The update is rated Important and applies to Red Hat Enterprise Linux 10 and its Extended Update Support variants. Administrators should apply the referenced Red Hat update to mitigate these risks.
Read Full Article →

Red Hat Product Errata RHSA-2026:41937 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41937 - Security Advisory Overview Updated Packages Synopsis Important: sssd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sssd is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2496556 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation BZ - 2496581 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass CVEs CVE-2026-14474 CVE-2026-14476 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM sssd-2.12.0-3.el10_2.1.src.rpm SHA-256: 6f658a4937b035e404bbc205a60117446999d5ea1cc85939da14414923bf70c5 x86_64 libipa_hbac-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: d317f72f2f31ef5d5eba4ab891b407e7a9eeff723db3b830d933826da377531e libipa_hbac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 5e41e731042cded314d81dc48bfef0a80ce601f4f1dbec1ed75e581563bf9aa1 libipa_hbac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 5e41e731042cded314d81dc48bfef0a80ce601f4f1dbec1ed75e581563bf9aa1 libsss_autofs-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 7b54e81d398bc7c977f734c8fb78f1dc758cd72cf89c621397a58a5c6b18fd50 libsss_autofs-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 03f528bd4006574565d157937fabe5850172ccf647da894521751cce6671ca99 libsss_autofs-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 03f528bd4006574565d157937fabe5850172ccf647da894521751cce6671ca99 libsss_certmap-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 86c8f545069ee37af8b35bc78420c082ca04aaa395ae3186f3df89b136dc43e2 libsss_certmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 268174cb6e917d95b023a3235b9e1752e5798de0175c93586d72696ecb83a630 libsss_certmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 268174cb6e917d95b023a3235b9e1752e5798de0175c93586d72696ecb83a630 libsss_idmap-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 8d288913d4b0cb3d974f3734527d6496de370ae7c824352fcc037c46b5ffd186 libsss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 55aa31ad0193df9acc5c2c45c13b523ea2649b7ffebad80a3fda1f37f8f2d164 libsss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 55aa31ad0193df9acc5c2c45c13b523ea2649b7ffebad80a3fda1f37f8f2d164 libsss_nss_idmap-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 051eb225d198e9b3facaf7bc55c4e5c085574e0fe9001eeaa5e7b24e0338ff1f libsss_nss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: c5c5660c6f6f2c14030f8f696a2d058cc995f69a8bf5c3dd5a595ab4ee26ecc9 libsss_nss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: c5c5660c6f6f2c14030f8f696a2d058cc995f69a8bf5c3dd5a595ab4ee26ecc9 libsss_sudo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: f3d8b4c90684ca994278149f9fff5d8307913035a4f1bd945f0b3348d183ca09 libsss_sudo-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 36b6b2c593ac373591744c55dbb9be4ffdee09319b0f274f8fa84f6c22e79230 libsss_sudo-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 36b6b2c593ac373591744c55dbb9be4ffdee09319b0f274f8fa84f6c22e79230 python3-libipa_hbac-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 860e5d6532d47c107cafae05a390f1585d8f4f58a160e316624cdd6c74efa789 python3-libipa_hbac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 143963ede463cd443e3b17bf2e57bd45abf387be47cf423a37247da22bff981a python3-libipa_hbac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 143963ede463cd443e3b17bf2e57bd45abf387be47cf423a37247da22bff981a python3-libsss_nss_idmap-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 1a73f1dfcecb498cafdeb16c2bc5c266de1c3ef44fb8390450f6ccf6a8b1973e python3-libsss_nss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 020ab484c527a3e62c167c62adb891ab0b788905013cba5e5ab60b1221ee5f2b python3-libsss_nss_idmap-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 020ab484c527a3e62c167c62adb891ab0b788905013cba5e5ab60b1221ee5f2b python3-sss-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 00b637d0cc74a8b7b7afecfc5936f9765115f4ecee0e77ba9bf5854c313ed351 python3-sss-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: c22f40213f3509696cde9fee9ab1d57be22f2fa71d54c3d3d65aad5959c2c91a python3-sss-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: c22f40213f3509696cde9fee9ab1d57be22f2fa71d54c3d3d65aad5959c2c91a python3-sss-murmur-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: c08af0c93133d49debf8096687417235fef87975cc638eae2da1bca414b38c60 python3-sss-murmur-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 4f7769db4a116a70302cf4ab3a9651c9a445d6bcc32679425385c62a71593bfe python3-sss-murmur-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 4f7769db4a116a70302cf4ab3a9651c9a445d6bcc32679425385c62a71593bfe python3-sssdconfig-2.12.0-3.el10_2.1.noarch.rpm SHA-256: 1c9b6ddbb8d0c187cb4ff47f03231d3684e437ec8a994ed53185533e75deef72 sssd-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 5e228b8ca86f1d4bc01bf95c442ec526268fc20a3a8cde93bf109d6875aa3a46 sssd-ad-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: e043abcb0bcd4f84ceedd6e5d6fa916085468eb6a5f5dc3c91e77947d0cfd7a5 sssd-ad-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: dbbefaa58f1dbae734093d078319e7b345c80ab7d67b42deab768ef3e3e2ff12 sssd-ad-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: dbbefaa58f1dbae734093d078319e7b345c80ab7d67b42deab768ef3e3e2ff12 sssd-client-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 0300ad37354a9db2d7020f774fbe9a526e44070024fae7b2476da497ad3bc76f sssd-client-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: e2db914f52fcc590961cc0996c3c809bb314e7bcd87142a8c29902f3af4a10f9 sssd-client-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: e2db914f52fcc590961cc0996c3c809bb314e7bcd87142a8c29902f3af4a10f9 sssd-common-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 8a3d45a11bd9f0b6878d198aae4391f7d60546a09d2c028de627e214b72b4b74 sssd-common-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 5d9675944c189b177ed4af84d953c9335f866d755e360b1cedef074007abbd91 sssd-common-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 5d9675944c189b177ed4af84d953c9335f866d755e360b1cedef074007abbd91 sssd-common-pac-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 47a58cd86731325989502930cb6246aa74a2b7774e4def0f79d1aab382451caf sssd-common-pac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: e51e98930b4c435cb191e31c0fab708f6a46940c299a6de11d4a401cfffd45f1 sssd-common-pac-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: e51e98930b4c435cb191e31c0fab708f6a46940c299a6de11d4a401cfffd45f1 sssd-dbus-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 0f3147d32f9815ba09a85f696dedd1d8a48d54e3ea80e5ba04ae8d3986251a50 sssd-dbus-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 2292926fad40fb9f909af3aa5c19a8acbb65c279ba2d87e0ba4fc8683c78c172 sssd-dbus-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 2292926fad40fb9f909af3aa5c19a8acbb65c279ba2d87e0ba4fc8683c78c172 sssd-debuginfo-2.12.0-3.el10_2.1.x86_64.rpm SHA-256: 101378ce8f90d965d894bb3a35df056c4b6dd19152f

Share this article