- What: Security update for sssd in Red Hat Enterprise Linux
- Impact: Systems using sssd may be vulnerable if not updated
Red Hat Product Errata RHSA-2026:49839 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:49839 - Security Advisory Overview Updated Packages Synopsis Important: sssd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sssd is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2496556 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation BZ - 2496581 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass CVEs CVE-2026-14474 CVE-2026-14476 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM sssd-2.9.6-4.el9_6.5.src.rpm SHA-256: a0e19157fb6ee88d2bcf313d62827d58f189bddbe2aa75f8ccca20360f90e59d x86_64 libipa_hbac-2.9.6-4.el9_6.5.i686.rpm SHA-256: 3cc037087576f3f83552fc6ef3e5ad96998f2579b938662253aa269a321df7e6 libipa_hbac-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 34f9a795451cca12ffa6a4831d0baa9118270f14465154cb27cd9788d7c5195a libipa_hbac-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 94c5d86d9dfe17989749eca2496158096cbeecce1bfdd178647564da9d51a5a1 libipa_hbac-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 1c113579ab6cfbf22bbc8e07ff4da26f9e5284c7f3952039071af5a647163bea libipa_hbac-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 1c113579ab6cfbf22bbc8e07ff4da26f9e5284c7f3952039071af5a647163bea libsss_autofs-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 9973382dae5e5a4b4b07bd30ebd4fa963d15f2b53f7a0abb8353120a2291c322 libsss_autofs-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: acba6ac7c110629cd544ed991319d342ff54334cd77fd432cd4278380af1f984 libsss_autofs-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: c2f59dac0a7dd3637099535b434d5ff8234127cc476039b5e522c9edaa699e00 libsss_autofs-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: c2f59dac0a7dd3637099535b434d5ff8234127cc476039b5e522c9edaa699e00 libsss_certmap-2.9.6-4.el9_6.5.i686.rpm SHA-256: 2214c575db79178d2937bd470c001d99d7515d801e7d3f1034041427842d302b libsss_certmap-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 60d20098f25cdd7fcdfa71cd0ba716938956da118308b1d35fb6603c7ec01be2 libsss_certmap-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: c6c8e5636f9f681affd4ce2a1165d543fc1a498316e39f28b613c2e57f6923a9 libsss_certmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 138c3586f6c4bf72df9513f85cab8ccd959d9711a257cbc78a6b5a1c4177d91d libsss_certmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 138c3586f6c4bf72df9513f85cab8ccd959d9711a257cbc78a6b5a1c4177d91d libsss_idmap-2.9.6-4.el9_6.5.i686.rpm SHA-256: bdd789199f147d0bdc3a76f42cd403b756fdfde70cbbfab11ad04fe5b6bda3dd libsss_idmap-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: b5734e40ace25d8efb309658037b11d2b74d2d7e45f8de42c98aaa0d7a5a090e libsss_idmap-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 4e4b98f0834dd3687305265ce0925f735b783f6df351ec65b265b811b17bc59d libsss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 2d79ee701e30ad1b425c5f5820e20f7ebb674a21bb0a44e9313e63fc9b765ac7 libsss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 2d79ee701e30ad1b425c5f5820e20f7ebb674a21bb0a44e9313e63fc9b765ac7 libsss_nss_idmap-2.9.6-4.el9_6.5.i686.rpm SHA-256: b265d609558b2d88a645b44d56e9598c645bf1ee5c67e672bfdd2acce640a372 libsss_nss_idmap-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 6310607ee135ebde42363a3b1f526e4b80e9b098c3ad4e585cabae13e61108d4 libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 9384ff402c0765934ce5455ef5af18ad1fc62322019471534a2419706bf02b15 libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 9536e692611e5bf79b5d2b54ec0a564c4d5632e00b1af6e87e686f0fcf580614 libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 9536e692611e5bf79b5d2b54ec0a564c4d5632e00b1af6e87e686f0fcf580614 libsss_simpleifp-2.9.6-4.el9_6.5.i686.rpm SHA-256: 211d72cb1ffab4c86c4b2b975f13f40821a4ecd2eb9e058b018c569df5e5ac5c libsss_simpleifp-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 7fbb0d07b8903e2989318e18070467fcc2c408a05540ecbf01491122c843fb16 libsss_simpleifp-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: bdb557006f7266c1ead001af1e9c0c848703736c8396eec52a3974ccec7ee148 libsss_simpleifp-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 109c6925e4278491034fabfd203bf3a1c49c67c0f555497948a96dbbfe76ab5f libsss_simpleifp-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 109c6925e4278491034fabfd203bf3a1c49c67c0f555497948a96dbbfe76ab5f libsss_sudo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 9b738a5437bd5d29dcbe1f3b28ac0ffc323628a966b76102742b79420bebc948 libsss_sudo-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 416d81402350cc57166a8011676a0598f01d4aff82ddfce43918e665ad632a62 libsss_sudo-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: b38f838863ff3dbf86459df251595d51ea6437b82b19f0fa76dc87654ac8a2c7 libsss_sudo-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: b38f838863ff3dbf86459df251595d51ea6437b82b19f0fa76dc87654ac8a2c7 python3-libipa_hbac-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: e3360a48c6aa9bea856c4b01db3937a8614079685df04ab6f0645f41df4a160c python3-libipa_hbac-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 356d409ebb16376112d4216ce901e4884d4a70489bfa9f22f49c13f3e48880f9 python3-libipa_hbac-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 3e87d42577060132886a786cada7c1c4032703f89c68855c989c7136d1943dd9 python3-libipa_hbac-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 3e87d42577060132886a786cada7c1c4032703f89c68855c989c7136d1943dd9 python3-libsss_nss_idmap-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 524f9d131249095571c505a1eb3427f7bf2c6d80fec111a78f39e2643f0d3c93 python3-libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: ffbf0367d0f9daf9496e3f4c5dce334777cba695c393365171722299692bdaac python3-libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 8914d61077c27ab48fc8412aa1376ae4c42c816c0cd485885e952fea5bdb94e7 python3-libsss_nss_idmap-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 8914d61077c27ab48fc8412aa1376ae4c42c816c0cd485885e952fea5bdb94e7 python3-sss-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 393c98f11bf7293758ac192da452d8bae4ada9074b2106570bb5c3d2da086c46 python3-sss-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 140933bd1ed58848afe085f916f831a6c9e9ba93ab0a09573a74dc5be07f63c7 python3-sss-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 657484a98b68b83c9ed8eb4cb9153eee78f58416690d709c296b9f6685d223a6 python3-sss-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 657484a98b68b83c9ed8eb4cb9153eee78f58416690d709c296b9f6685d223a6 python3-sss-murmur-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: da9c458a591f68d5657b39128d9b90c7342416d133e75b749b7d4a14dfd542a2 python3-sss-murmur-debuginfo-2.9.6-4.el9_6.5.i686.rpm SHA-256: 937e2c23b20c0a8ad3a5ebe42667f89f1b05dae5c823f671d8d2395e49e2cb9b python3-sss-murmur-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 47036aa9217543694a75fe3ac24319a1469a82438eb502ce0ad7d4212e07e917 python3-sss-murmur-debuginfo-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 47036aa9217543694a75fe3ac24319a1469a82438eb502ce0ad7d4212e07e917 python3-sssdconfig-2.9.6-4.el9_6.5.noarch.rpm SHA-256: 79e3848303aa08e3abd101f7fe4be3af4491286f9806a3de9eecf3024ef33164 sssd-2.9.6-4.el9_6.5.x86_64.rpm SHA-256: 65cdfa0d9c89c49570f844c4f2304ac83e901bcc38bae180c350230dc4