- What: Security update for sssd in Red Hat Enterprise Linux
- Impact: Systems using sssd need to apply the update to address security issues
Red Hat Product Errata RHSA-2026:49843 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:49843 - Security Advisory Overview Updated Packages Synopsis Important: sssd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sssd is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2496556 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation BZ - 2496581 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass CVEs CVE-2026-14474 CVE-2026-14476 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM sssd-2.8.2-5.el9_2.7.src.rpm SHA-256: 5345802ddb5f5ea6eba6c35493c0093ce96d93c968194b6c02e146124035301f x86_64 libipa_hbac-2.8.2-5.el9_2.7.i686.rpm SHA-256: 5a19e5070018b079b354a6a83ad3ba278487719a7a00b9bc3bd0bb0047ce3f11 libipa_hbac-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: c885ede725d862b9a0319f9628df72f93f750bcada87d952c0c176ca38b50695 libipa_hbac-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: c48eb419c86b4452d8f052def0ffc23214a22ff70156838319cc0e996c971358 libipa_hbac-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 9e5192d7f323203ea7c48203927880ddbd2915c8283e81923bafe09d13648d05 libipa_hbac-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 9e5192d7f323203ea7c48203927880ddbd2915c8283e81923bafe09d13648d05 libsss_autofs-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: fb58c6f467bf23da34f6714ed64b8e65b8d938d786b496ffa36b0619af049fbb libsss_autofs-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: bc31caf06a884350785ed8a0fc5ba66c543941b5102188cf4e23d604dd5b8c90 libsss_autofs-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: be49797076541c7420fe4abf0a3169643ea46c980cafa3040a8bda84b6315e67 libsss_autofs-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: be49797076541c7420fe4abf0a3169643ea46c980cafa3040a8bda84b6315e67 libsss_certmap-2.8.2-5.el9_2.7.i686.rpm SHA-256: 9ba0f6cacf3fb8ce7ebf72b6c66dd1b6280f9cfa9ba4ccb35b0ac2767092fd6d libsss_certmap-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: e9f0617236dca646942387c6c63a3ce4a83967e949937424411aa1b2fb5707eb libsss_certmap-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: c3554e1bcf2a1f51eaff6fd9f5fe6c50d310b61878a6122d40bf146a6b12b996 libsss_certmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 76649f5a8cb268bf4169fd852f43f0d6003efad4ae1d60a5d02698d9793425dd libsss_certmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 76649f5a8cb268bf4169fd852f43f0d6003efad4ae1d60a5d02698d9793425dd libsss_idmap-2.8.2-5.el9_2.7.i686.rpm SHA-256: b64486e23edf69b1b1c12a208ec0f868c2395815fab71cb7edafb66104d8dbce libsss_idmap-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 40f52e09f77d7f1287b04249755f16af2aacf60f4e525f56e0fe9a5b13c585cf libsss_idmap-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: c1b9a0db2ce7c611edb618a693bfc77ea5d53165e99c41de7312d77f29edf6ea libsss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: fde798eed7847c13bc3078f7adad8cb5a125291b09aed2a8bab8d82b2a7a2f78 libsss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: fde798eed7847c13bc3078f7adad8cb5a125291b09aed2a8bab8d82b2a7a2f78 libsss_nss_idmap-2.8.2-5.el9_2.7.i686.rpm SHA-256: 6a0ed76df888de037625c702ff20a7276d968f9c3f02ebfc1bb8150949a768d4 libsss_nss_idmap-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 0f8675ac33d6db6e565ac445c72b7fd2e3d422c67398215f0e32f130a28aeaeb libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: bc2efe0fea5b4f7761a812d10294f5629923b6070ca4a8f4c46355ec5c9202e3 libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 4ddadde7ca6a079c7a57e078f3a9268cd5b0ad8fca1b935c711487629aae6874 libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 4ddadde7ca6a079c7a57e078f3a9268cd5b0ad8fca1b935c711487629aae6874 libsss_simpleifp-2.8.2-5.el9_2.7.i686.rpm SHA-256: 62955bdfba879f4726e58741835da2a751767aaf4e8442d499dac05aae42bea0 libsss_simpleifp-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: acc4e4141799010c64cf31bd4be66be637780439149eab5bcf5d5317c8d207bc libsss_simpleifp-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 2fdc01cf66088fd7bcbbaabbfdb1c7d710137132f436f8e1bd782cd09937fe43 libsss_simpleifp-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 4d60db67e466222e1d99c18f511f5ec823270216e55b7f91ee3af0807d91713e libsss_simpleifp-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 4d60db67e466222e1d99c18f511f5ec823270216e55b7f91ee3af0807d91713e libsss_sudo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: b3e26d7ce0e6c295abb9efabc82a4d0a171fb776f8a4d1fb5fc0bb3dcd721300 libsss_sudo-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 198ec5a15928ec1af4198a2b83daa4958a407adf07aa65b65a7169b5c7c47e3f libsss_sudo-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 1f34c103b8dfda4f3c5b69ae8718166c700d0d3cd93838c1d97e16b59810e18d libsss_sudo-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 1f34c103b8dfda4f3c5b69ae8718166c700d0d3cd93838c1d97e16b59810e18d python3-libipa_hbac-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 919335edc9e04df10f4c1935abd4af3f0d61db519e190cd84e5fc8117f87d369 python3-libipa_hbac-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 332e1fcd26057d39e2229dfa70c34891da63879c25076036e7eb2c2753aea32d python3-libipa_hbac-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 9b0469a1051957ff090fdb4bc91652f1368bbe8d34a25e01bf0b02c78ddc7730 python3-libipa_hbac-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 9b0469a1051957ff090fdb4bc91652f1368bbe8d34a25e01bf0b02c78ddc7730 python3-libsss_nss_idmap-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 1b39c738105a91b9b3b64d181de83ae2f155e3873d2bce67aefb652e051639b9 python3-libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 30fe82522e3bb7f59cb01bdf82296c2a8c7a66c3f227a4162c7b91b6d54e04ae python3-libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 1b48eece39c8759dbec8911cd22ebb94f58d4bf6391059abcbb234392b3af1a9 python3-libsss_nss_idmap-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 1b48eece39c8759dbec8911cd22ebb94f58d4bf6391059abcbb234392b3af1a9 python3-sss-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: d2e984b8a42050b920605bb4926d1f83832b388f175b6782e4fd84ca083470e5 python3-sss-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 83c7158e791b008d6e138caa89f0e3489f2b6d4f74bd9a4c5888cded585bdd86 python3-sss-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 5799e94c2ee4542e577546d09bf0debda4aa76c5b9bb0da57bfb7eba6ddda628 python3-sss-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 5799e94c2ee4542e577546d09bf0debda4aa76c5b9bb0da57bfb7eba6ddda628 python3-sss-murmur-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: f279cccdfb298dde6513d148f33bc3299776de8b6fdeee598e013c4e4878a642 python3-sss-murmur-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: f9262ecdc07d4b63e49dc7b0bb9ae47f1f7596e23a2b55407094116918e2233b python3-sss-murmur-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 2281ac5a01e39c25d887e49d1b35555e06c5e359d2d767e580707362fca297aa python3-sss-murmur-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 2281ac5a01e39c25d887e49d1b35555e06c5e359d2d767e580707362fca297aa python3-sssdconfig-2.8.2-5.el9_2.7.noarch.rpm SHA-256: e101fb11155852e00d92a847af88fd70de4fa343bb08beebe8c28cda5c1a9e2d sssd-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 558fc2b7c07a3b9e5ce9901424429c25dc51835777a8465305f9fa45ee95234c sssd-ad-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: df4122b47cb39290fd4d10a3f67b5e3654c5a902ab3a5ee34abfe3ace9d8872b sssd-ad-debuginfo-2.8.2-5.el9_2.7.i686.rpm SHA-256: 2a507872e1414bd3c1444157c8970f6d30776e901cbc8cdc4b8547cebbfa8642 sssd-ad-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: a18d827fbcab9c6f46f86e7d6760394dafeeeeee04b2e2762da2530eaa45e4b6 sssd-ad-debuginfo-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: a18d827fbcab9c6f46f86e7d6760394dafeeeeee04b2e2762da2530eaa45e4b6 sssd-client-2.8.2-5.el9_2.7.i686.rpm SHA-256: 2465cbf40a04b08aa1ccc06efb45dfd9aefa5144c2300d6f019331292207621a sssd-client-2.8.2-5.el9_2.7.x86_64.rpm SHA-256: 3335b36eeac472b4071a920595c9151fd1f3d057