For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The System Security Services Daemon (SSSD) service provides a set of
daemons to manage access to remote directories and authentication
mechanisms. It also provides the Name Service Switch (NSS) and the
Pluggable Authentication Modules (PAM) interfaces toward the system, and a
pluggable back-end system to connect to multiple different account sources.
The following packages have been upgraded to a later upstream version: sssd
(2.2.0). (BZ#1687281)
Security Fix(es):
* sssd: improper implementation of GPOs due to too restrictive permissions
(CVE-2018-16838)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.1 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2018-16838 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/
Red Hat Enterprise Linux BaseOS (v. 8):
Source:
sssd-2.2.0-19.el8.src.rpm
aarch64:
libipa_hbac-2.2.0-19.el8.aarch64.rpm
libipa_hbac-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_autofs-2.2.0-19.el8.aarch64.rpm
libsss_autofs-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_certmap-2.2.0-19.el8.aarch64.rpm
libsss_certmap-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_idmap-2.2.0-19.el8.aarch64.rpm
libsss_idmap-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_nss_idmap-2.2.0-19.el8.aarch64.rpm
libsss_nss_idmap-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_simpleifp-2.2.0-19.el8.aarch64.rpm
libsss_simpleifp-debuginfo-2.2.0-19.el8.aarch64.rpm
libsss_sudo-2.2.0-19.el8.aarch64.rpm
libsss_sudo-debuginfo-2.2.0-19.el8.aarch64.rpm
python3-libipa_hbac-2.2.0-19.el8.aarch64.rpm
python3-libipa_hbac-debuginfo-2.2.0-19.el8.aarch64.rpm
python3-libsss_nss_idmap-2.2.0-19.el8.aarch64.rpm
python3-libsss_nss_idmap-debuginfo-2.2.0-19.el8.aarch64.rpm
python3-sss-2.2.0-19.el8.aarch64.rpm
python3-sss-debuginfo-2.2.0-19.el8.aarch64.rpm
python3-sss-murmur-2.2.0-19.el8.aarch64.rpm
python3-sss-murmur-debuginfo-2.2.0-19.el8.aarch64.rpm
sssd-2.2.0-19.el8.aarch64.rpm
sssd-ad-2.2.0-19.el8.aarch64.rpm
sssd-ad-debuginfo-2.2.0-19.el8.aarch64.rpm
sssd-client-2.2.0-19.el8.aarch64.rpm
Read the Full Advisory
An update for sssd is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server
1598457 - Attributes not present in Global Catalog can be removed from the cache during GC lookups
1638295 - sssctl user-checks does not show custom IFP user_attributes
1640820 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions
1657665 - Error accessing files on samba share randomly
1660461 - responders chain requests that were issued before reconnection to sssd_be
1661182 - sss_cache prints spurious error messages when invoked from shadow-utils on package install
1665388 - SSSD netgroups do not honor entry_cache_nowait_percentage
1665867 - proxy provider is not working with enumerate=true when trying to fetch all groups
1667045 - Missing sssd-files in last section(SEE ALSO) of sssd man pages
1667252 - crash when requesting extra attributes
1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8
1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration
1676385 - pam_sss with smartcard auth does not create gnome keyring
1677994 - sssd config-check reports an error for a valid configuration option
1681279 - AD user not found after establishing trust and restarting sssd
1686154 - sudorule matching when no host or hostcat set
Get the latest Linux and open source security news straight to your inbox.