Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:49842: Important: sssd security update

  • What: Security update for sssd in Red Hat Enterprise Linux
  • Impact: Systems using sssd need to apply the update to address security issues
Read Full Article →

Red Hat Product Errata RHSA-2026:49842 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:49842 - Security Advisory Overview Updated Packages Synopsis Important: sssd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sssd is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2496556 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation BZ - 2496581 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass CVEs CVE-2026-14474 CVE-2026-14476 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM sssd-2.8.2-4.el8_8.4.src.rpm SHA-256: b48122597e3cbeea4bddd9473da6368bf4ff5ded8f8ee9891e8b6daed2633aec x86_64 libipa_hbac-2.8.2-4.el8_8.4.i686.rpm SHA-256: 843538cc52fdc72c7fa16b35880c1cec24776dff9d3deeb3ff12984ccdb80262 libipa_hbac-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 37e86ffe7968b3f52f94de6c0ffe49e70750d2f1868b02ae73ed2381ef5d0416 libipa_hbac-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 10a02547d7fbbdda647a6580033665e797fcee8d493d21d048c01d1b179e072e libipa_hbac-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: b049f248a883d932b92cbe27fc8740bd45802132ed5aec4231f81ca2682a578b libipa_hbac-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: b049f248a883d932b92cbe27fc8740bd45802132ed5aec4231f81ca2682a578b libsss_autofs-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 46bae653f9001db1829059c168ed2b227e34acbe84d85346a7568e885a7abdc9 libsss_autofs-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 98ea818c78538c0f732638cea0efff19869dfe07e3613140c731a550e56dacbb libsss_autofs-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d5f7d66d9d97d8411ecfbd222a80b42ba675770a22c11f21cc91dbe2c98cb790 libsss_autofs-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d5f7d66d9d97d8411ecfbd222a80b42ba675770a22c11f21cc91dbe2c98cb790 libsss_certmap-2.8.2-4.el8_8.4.i686.rpm SHA-256: 2b12d6062c12a5c53a44ed9283a3c4147a63588c556440fcd5be7a7ea3a6d3b1 libsss_certmap-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 8e8af813d22c606e83f01147db6423c41aa34e61f97e666fac21872ee7c49de6 libsss_certmap-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 8e35e07f485a489948de8accd52f17908e0fa168710bece1d9a56a81e62b1062 libsss_certmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d25e626348f60cbf292488fea6783de7584f689d1c209d979f2e5e27e38c850e libsss_certmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d25e626348f60cbf292488fea6783de7584f689d1c209d979f2e5e27e38c850e libsss_idmap-2.8.2-4.el8_8.4.i686.rpm SHA-256: 6636c13e2c6c8b707fb050da30aefc391e32a5f43d5aeb31e5c2d23f7a0e36dd libsss_idmap-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 53bc4585076cab0da02d961140df8066513c1690857996718742e9b90a3acc4b libsss_idmap-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 294a2dd03d867941d24dc64d9e8fa895fbf947dcabf15385900144205748edd3 libsss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: a06750168bcabe79477f7cb6f021253e2ce5c4647c7ca9e00d42aa730d97d853 libsss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: a06750168bcabe79477f7cb6f021253e2ce5c4647c7ca9e00d42aa730d97d853 libsss_nss_idmap-2.8.2-4.el8_8.4.i686.rpm SHA-256: a4b80eed3a32d654309e1133379cacc14b1100d5d9d2ce0ad736ec0ea2f272ce libsss_nss_idmap-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d9b7b200cb10f9c6450615b407af913d79e2f8be303a9b8a9a606172970913f7 libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 213c8daf28fc0282ffa4a60e856b47d5bdd4eec33ac25d9b0d8fa0f3bd0c909b libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d6b84ea2641eb5dcf8a62e49eb4a8e34085f6fe3456848d93b3cbe42a075f3c8 libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: d6b84ea2641eb5dcf8a62e49eb4a8e34085f6fe3456848d93b3cbe42a075f3c8 libsss_simpleifp-2.8.2-4.el8_8.4.i686.rpm SHA-256: d0079135c737397a73a00a62860a9c7da26f7925f7ff29e8188e29f96633369d libsss_simpleifp-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 36d7b0a66edd9651557cceab957fc6647143ce338506e276f95b8b2abf4fda1c libsss_simpleifp-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: c4714b51fe8b9bbdb592c8f73004127b60acec79a40d2ebc3ad6906098fedc7d libsss_simpleifp-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 146016c5d3e98bff5679af474987a90f6e1f7091d619ba1540a5864c1b06f5fd libsss_simpleifp-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 146016c5d3e98bff5679af474987a90f6e1f7091d619ba1540a5864c1b06f5fd libsss_sudo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 1ac3832e3101361a82099df2e3869ce35cb7afd2eeb07d1f880b9f710dbffeb4 libsss_sudo-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 389c3d86d03b642e69226f715bfa3b919e594db8eced13c45716582bf1c83301 libsss_sudo-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: e4fb01b05eed5f01f2bd30a551309f4ee1198d3c21b3c9bfe1f61866fbc5c2cb libsss_sudo-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: e4fb01b05eed5f01f2bd30a551309f4ee1198d3c21b3c9bfe1f61866fbc5c2cb python3-libipa_hbac-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: f5f28a2f9b1b4edd98dd1da867a21f5068a360fe107efa7bdb29ba725724922b python3-libipa_hbac-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: b7a7cf3607bb9e708d76b1643603abbe52392b72e057cf0863863a811c97a0c6 python3-libipa_hbac-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 72a0703650308f8c6265d787b89810da556730e08484bba723f3094862c67991 python3-libipa_hbac-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 72a0703650308f8c6265d787b89810da556730e08484bba723f3094862c67991 python3-libsss_nss_idmap-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 6058e0351c38c7ca6f035e098e35dcd829eeae8a6de495f74f00630fd7a94c7a python3-libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: b1ddef4633825941db793b68de80787bdc65766d9c559f917c5c6ef1d1b6431b python3-libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 1ff6fd29bfb6fe1094140f485c781f87b4286bf4fa35ee6c7d1b498eeda94a54 python3-libsss_nss_idmap-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 1ff6fd29bfb6fe1094140f485c781f87b4286bf4fa35ee6c7d1b498eeda94a54 python3-sss-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 99649c415dc8fa1c2edde3da885ac58b0ed1a33ed3b9415ab261d20bb5f64678 python3-sss-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: dffe619040f81371beffbbb9c2ca79115f39da33a44b3d4edc719265708f4055 python3-sss-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 5166dc42dd8fd9c76ef29048b09ca1bf8635fd5c503edc0592947bea17a8cbf0 python3-sss-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 5166dc42dd8fd9c76ef29048b09ca1bf8635fd5c503edc0592947bea17a8cbf0 python3-sss-murmur-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 575fd79828185c9bfa8a433e3d580cf31b78a63a8340b8c346d37285e1613bf5 python3-sss-murmur-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: eafb12d9912d951125e31d918a6991971fcb456df576e42781f23405a5674ba5 python3-sss-murmur-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 6a19f979612a809b7af65e80b8a772a58d528567bc053f45e8d8e2e1091f6d42 python3-sss-murmur-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 6a19f979612a809b7af65e80b8a772a58d528567bc053f45e8d8e2e1091f6d42 python3-sssdconfig-2.8.2-4.el8_8.4.noarch.rpm SHA-256: 6aa883afdcb2dc7b768ba5924ac45bc337d7ffb23f936bb123a5fb947301f103 sssd-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: fef799213ec259fda80c8f9ee74babe5505ceb8667625507d02b17ff9d25d6a6 sssd-ad-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: b4e92d6dc2db45cd6308a20a22534c3a3619d4119779107c11c430bd9557e87c sssd-ad-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 60f2930ff1caca5aa4e8c3c50bd02104722d216dcb31c91bd95f803975365964 sssd-ad-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: fa33f5c3bd8467705a4059b81282f52e74809781d7b9fcab0baceab9b145563f sssd-ad-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: fa33f5c3bd8467705a4059b81282f52e74809781d7b9fcab0baceab9b145563f sssd-client-2.8.2-4.el8_8.4.i686.rpm SHA-256: 18d1c537d6cf75fcaffc42a5d265123fe7bb8047c8e93677bfe004462d024550 sssd-client-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: 4738501d5987efe2b08fd3a8efd56bc5750ac2da9bada02d10602e8125d68a33 sssd-client-debuginfo-2.8.2-4.el8_8.4.i686.rpm SHA-256: 869e14920a3a8cd3533c1ed9b7105376c90d6ddb8036da52adae44faebe7178b sssd-client-debuginfo-2.8.2-4.el8_8.4.x86_64.rpm SHA-256: c9e4e127b70807574a0e65abd47902397764603a31c64b037ee62add4d3d7

Share this article