Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:49840: Important: sssd security update

  • What: Security update for sssd in Red Hat Enterprise Linux
  • Impact: Systems using sssd need to apply the update to address security issues
Read Full Article →

Red Hat Product Errata RHSA-2026:49840 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:49840 - Security Advisory Overview Updated Packages Synopsis Important: sssd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sssd is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2496556 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation BZ - 2496581 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass CVEs CVE-2026-14474 CVE-2026-14476 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM sssd-2.9.4-6.el9_4.5.src.rpm SHA-256: ec91692d5f9aa04b9c30044ec539a9bd4d326bed913fa9f3f254b351abab8508 x86_64 libipa_hbac-2.9.4-6.el9_4.5.i686.rpm SHA-256: 7379a9af659b6c72451fb509abae33381ebb7855a62eb8875e0f84eede00ff64 libipa_hbac-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 271c5c59ff00cac5d4040b518991d99bad01e0c53007706c74e3a94fcd7da689 libipa_hbac-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: b142d8ee65bf916d7a0692677f74beb6790028ff9d2baf0d87a65f8ea4e612d2 libipa_hbac-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a03bfdab866f241fc2fadd25120e153c61837074e079ecf25b122a5246756ef4 libipa_hbac-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a03bfdab866f241fc2fadd25120e153c61837074e079ecf25b122a5246756ef4 libsss_autofs-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 5fc10ca5fdeb767d0201fcd6fab4dc69dcc860b7e0113132564bdb92bc8b1543 libsss_autofs-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: b4e573ac5722b0812143dbda3fa4fab1d3fcf01183a34c97d38cccf21d336eb2 libsss_autofs-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: aa0497dcc2e6f8211ea53397ba8749a717074836fc6b2369984d3fa90ad675bf libsss_autofs-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: aa0497dcc2e6f8211ea53397ba8749a717074836fc6b2369984d3fa90ad675bf libsss_certmap-2.9.4-6.el9_4.5.i686.rpm SHA-256: 3e48d7aa8bfe91bbc98f4a109b1be4de43c3fddc0b1a1cbe521a47212118490e libsss_certmap-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 915683e4c10767c9d9b4bbbaa73e0e855b93ee33f4c6c806bcf859c7401c60c2 libsss_certmap-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 8b37e081c671225cc40e6d358b9380b8320f8cb4826df575d5150ee6c3593310 libsss_certmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 9eac4b6c17395fa6f4a38cbf900ad1b910b23de34d87275f0a3c716fd4beb718 libsss_certmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 9eac4b6c17395fa6f4a38cbf900ad1b910b23de34d87275f0a3c716fd4beb718 libsss_idmap-2.9.4-6.el9_4.5.i686.rpm SHA-256: bebc8da6a022d9683d0bb00bc868846b13a9e8b46b5a19feae2c53ef877ab8c1 libsss_idmap-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 4ab8ec8c126b789d8275cf855b2e4d02a96f9c25269d044fb1d67151a59ee145 libsss_idmap-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 7adfa1cb1bbb8736032632c175333876eb652504f3fae3288a81f1a2fb097f89 libsss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a6102cc927b818cff7ea54d01adee99b934f36234706ed1b15243ba4e0121fb3 libsss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a6102cc927b818cff7ea54d01adee99b934f36234706ed1b15243ba4e0121fb3 libsss_nss_idmap-2.9.4-6.el9_4.5.i686.rpm SHA-256: 296078bc4b3beae97be9df0a7a1b271a580f510953a54e0018fdc1f03f34436a libsss_nss_idmap-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 79a8cade8a778789f0f9a453d63845cfcbca5e8a633f33f11f08e3687fa6c714 libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: abd32eff72168af65796778ebb69df2f32fcc576b8f38632e1001ef1d72482a6 libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 19b62eb98af06f4fd6fe75931359a3ddd7b9305c96f511a7224111063150fd2d libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 19b62eb98af06f4fd6fe75931359a3ddd7b9305c96f511a7224111063150fd2d libsss_simpleifp-2.9.4-6.el9_4.5.i686.rpm SHA-256: 00024510c44bf246a57da6f1a22fea6dbf6e320f4054d781baed6abc031bbc03 libsss_simpleifp-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 901b1adda984f0f15830d4ecb4f97e2981967f4de5885fa9bfc3d6f90c892ea4 libsss_simpleifp-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: b25b2dde73cd36ef2d542d594a6173723173347f1b81fcea1cef74ab20181259 libsss_simpleifp-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: aecacd5e4ae144747e4b8484cca5bcd5c0fc1f7d9f029bbb1f5ce53832a449eb libsss_simpleifp-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: aecacd5e4ae144747e4b8484cca5bcd5c0fc1f7d9f029bbb1f5ce53832a449eb libsss_sudo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 5b00f16774086a262c2973561f3dbd019a63808e2907190427b412373667d54e libsss_sudo-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 5defc5f23eb1d35a8aa941a1a964f9c7161e9fba0407e02248553eb442fc5beb libsss_sudo-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: c1f3222366bfe0743d77715857fbee2adfeb5c6c8f49f6f7e6c329f7b6b9d0f8 libsss_sudo-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: c1f3222366bfe0743d77715857fbee2adfeb5c6c8f49f6f7e6c329f7b6b9d0f8 python3-libipa_hbac-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 25e582918d11bfa38fec1b5a56fa8e143790274977fc141c6938ea833e75d502 python3-libipa_hbac-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 88f6523b84be187cfd372228590e61db97ca28cac5678ec0503ee32715634eda python3-libipa_hbac-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 247ad225386fdb6f46c03d26633c373aaab489833e14e9b94435e4051810df6b python3-libipa_hbac-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 247ad225386fdb6f46c03d26633c373aaab489833e14e9b94435e4051810df6b python3-libsss_nss_idmap-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a32b251e22cdaed85229c72758d84bfda85a5fe4d0123b9580db94e833c59f26 python3-libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: d0c2a5199b08c3073120cad931bb644e2964e2bfdff3dbafecffc8d6e3f9d65b python3-libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 50ab618363ee03b8261d9c62dcf88b663f2e9af4f3ecf5a2310c30a6f0a9d3b6 python3-libsss_nss_idmap-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 50ab618363ee03b8261d9c62dcf88b663f2e9af4f3ecf5a2310c30a6f0a9d3b6 python3-sss-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 887971d092fdf83b2d74f7531bf02d8efdcc30529eb5ff7182385011682ab613 python3-sss-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 291423fed48dbe1d4696b7b0c90ea6c32ca6f6b02e9301cb558d23e67d3c1303 python3-sss-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: b10184e66b29d29d700f811222ccfbef647bb99fe6935a0473bdd88057616a4e python3-sss-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: b10184e66b29d29d700f811222ccfbef647bb99fe6935a0473bdd88057616a4e python3-sss-murmur-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: a424ae0193a77145296fb684a44fa79361742350eb0ca5f6457a5ea6508c2354 python3-sss-murmur-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 4de9058e0d8a3e9d7d3eb663db483bf798df6dd09f2eeb30b54361dec90beb45 python3-sss-murmur-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: eb14ab77a3a648999e9624612875cd7c4e831563cf2c0d42fea387b60ddefae5 python3-sss-murmur-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: eb14ab77a3a648999e9624612875cd7c4e831563cf2c0d42fea387b60ddefae5 python3-sssdconfig-2.9.4-6.el9_4.5.noarch.rpm SHA-256: 288322bcda33665e3290331a302d926a4c26ff88e54200bdb58a1de167cd93ca sssd-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 08703c2434100b069d0986d515be9a7b38a0a9b0ea81efaf17e620a93b4a7985 sssd-ad-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 2019c2d66908fba2e84821bacab261cdf234d1d95bea6e27464744595b8c2b7f sssd-ad-debuginfo-2.9.4-6.el9_4.5.i686.rpm SHA-256: 4c0afd6d22b7112b15bcf0c688c1386573ed6f53a1f95787dc629f603a919695 sssd-ad-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: dad0f37a16eb36275c69f4630bddc477ff64521502ccc1f66558810d09135ffe sssd-ad-debuginfo-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: dad0f37a16eb36275c69f4630bddc477ff64521502ccc1f66558810d09135ffe sssd-client-2.9.4-6.el9_4.5.i686.rpm SHA-256: 9dae05b1e31ba5199ef6324837e232e46bdb8e54d3293c1740e780c6767c497e sssd-client-2.9.4-6.el9_4.5.x86_64.rpm SHA-256: 0e4362982debd9bce9d2585ab7358b995e749865

Share this article