Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2024:1577-1 Crucial Security Updates for SSSD Across Multiple Distros

suse
Calendar Grey August 19, 2024
Dist Suse Esm H88
Implement essential sssd security patches for SUSE Linux Enterprise to tackle significant vulnerabilities and maintain system integrity.
* bsc#1160688 * bsc#1223100 * jsc#PED-7677 * jsc#SLE-9298

Summary

## This update for sssd fixes the following issues: Security fixes: \- CVE-2023-3758: Fixed race condition during authorization that lead to GPO policies functioning inconsistently (bsc#1223100) Other fixes: * Extend sssctl command line tool to manage the cached GPOs (jsc#PED-7677) * SSSD GPO host entries are ignored if computer cn does not match it's samaccountname (jsc#SLE-9298) (bsc#1160688) * SSSD should accept host entries from GPO's security filter (jsc#SLE-9298) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1577=1

References

* bsc#1160688

* bsc#1223100

* jsc#PED-7677

* jsc#SLE-9298

Cross-

* CVE-2023-3758

CVSS scores:

* CVE-2023-3758 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

An update that solves one vulnerability, contains two features and has one

security fix can now be installed.

##

* https://www.suse.com/security/cve/CVE-2023-3758.html

* https://bugzilla.suse.com/show_bug.cgi?id=1160688

* https://bugzilla.suse.com/show_bug.cgi?id=1223100

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1577-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here