Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves two vulnerabilities can now be installed.. # Security update for sssd Announcement ID: SUSE-SU-2026:3025-1 Release Date: 2026-07-15T09:49:27Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3025=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3025=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 *python3-sss_nss_idmap-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * libnfsidmap-sss-debuginfo-2.10.2-150600.3.53.1 * python3-sss_nss_idmap-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * python3-ipa_hbac-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * python3-ipa_hbac-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * libnfsidmap-sss-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * python3-sss-murmur-debuginfo-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * python3-sss-murmur-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * openSUSE Leap 15.6(x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * openSUSE Leap 15.6 (aarch64_ilp32) * sssd-64bit-2.10.2-150600.3.53.1 * sssd-64bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 *libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 *libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 . Two important vulnerabilities in sssd resolved by the latest openSUSE update are crucial for maintaining system security.. openSUSE updates, sssd vulnerabilities, security patches. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for sssd ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21290-1 Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for sssd fixes the following issues - CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). - CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1201=1 Package List: - openSUSE Leap 16.0: libipa_hbac-devel-2.10.2-160000.3.1 libipa_hbac0-2.10.2-160000.3.1 libnfsidmap-sss-2.10.2-160000.3.1 libsss_certmap-devel-2.10.2-160000.3.1 libsss_certmap0-2.10.2-160000.3.1 libsss_idmap-devel-2.10.2-160000.3.1 libsss_idmap0-2.10.2-160000.3.1 libsss_nss_idmap-devel-2.10.2-160000.3.1 libsss_nss_idmap0-2.10.2-160000.3.1 python3-ipa_hbac-2.10.2-160000.3.1 python3-sss-murmur-2.10.2-160000.3.1 python3-sss_nss_idmap-2.10.2-160000.3.1 python3-sssd-config-2.10.2-160000.3.1 sssd-2.10.2-160000.3.1 sssd-ad-2.10.2-160000.3.1 sssd-cifs-idmap-plugin-2.10.2-160000.3.1 sssd-dbus-2.10.2-160000.3.1 sssd-ipa-2.10.2-160000.3.1 sssd-kcm-2.10.2-160000.3.1 sssd-krb5-2.10.2-160000.3.1 sssd-krb5-common-2.10.2-160000.3.1 sssd-ldap-2.10.2-160000.3.1 sssd-proxy-2.10.2-160000.3.1 sssd-tools-2.10.2-160000.3.1 sssd-winbind-idmap-2.10.2-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html . Install critical patches for sssd vulnerabilities on openSUSE Leap 16.0 to secure LDAP provider and GPO cache.. sssd security patch, openSUSE vulnerabilities, LDAP authentication fix, Kerberos security update. . Severity: Important. LinuxSecurity.com Team
CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 - rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process - rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5acfb0243b 2026-07-11 01:06:30.201372+00:00 -------------------------------------------------------------------------------- Name : sssd Product : Fedora 44 Version : 2.13.1 Release : 2.fc44 URL : https://github.com/SSSD/sssd/ Summary : System Security Services Daemon Description : Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd subpackage is a meta-package that contains the daemon as well as all the existing back ends. -------------------------------------------------------------------------------- Update Information: CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 - rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process - rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass - rhbz#2497651: CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Sumit Bose - 2.13.1-2 - CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 - rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process - rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitizedgPCFileSysPath allows Kerberos authentication bypass - rhbz#2497651: CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494777 - CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494777 [ 2 ] Bug #2497650 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497650 [ 3 ] Bug #2497651 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497651 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5acfb0243b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
SSSD could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8355-1 June 01, 2026 sssd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: SSSD could be made to crash if it received specially crafted input. Software Description: - sssd: System Security Services Daemon Details: It was discovered that SSSD did not properly handle raw bytes in the PAM passkey responder. A local attacker could possibly use this issue to cause the SSSD PAM responder to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS sssd 2.12.0-1ubuntu5.1 Ubuntu 25.10 sssd 2.10.1-2ubuntu5.2 Ubuntu 24.04 LTS sssd 2.9.4-1.1ubuntu6.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8355-1 CVE-2026-6245 Package Information: https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.1 https://launchpad.net/ubuntu/+source/sssd/2.10.1-2ubuntu5.2 https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.5 . A critical advisory for Ubuntu users regarding an important sssd issue leading to potential denial of service.. Ubuntu Advisory SSSD Security Denial Service. . Severity: Important. LinuxSecurity.com Team
SSSD could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8355-1 June 01, 2026 sssd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: SSSD could be made to crash if it received specially crafted input. Software Description: - sssd: System Security Services Daemon Details: It was discovered that SSSD did not properly handle raw bytes in the PAM passkey responder. A local attacker could possibly use this issue to cause the SSSD PAM responder to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS sssd 2.12.0-1ubuntu5.1 Ubuntu 25.10 sssd 2.10.1-2ubuntu5.2 Ubuntu 24.04 LTS sssd 2.9.4-1.1ubuntu6.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8355-1 CVE-2026-6245 Package Information: https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.1 https://launchpad.net/ubuntu/+source/sssd/2.10.1-2ubuntu5.2 https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.5 . A high-level advisory for Ubuntu on SSSD's security issue leading to potential crashes. Update now to avoid service interruptions.. Ubuntu system update, SSSD security issue, denial of service risk. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for sssd Announcement ID: SUSE-SU-2026:20019-1 Release Date: 2026-01-02T16:58:16Z Rating: important References: * bsc#1244325 * bsc#1251827 Cross-References: * CVE-2025-11561 CVSS scores: * CVE-2025-11561 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-11561 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11561 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for sssd fixes the following issues: * CVE-2025-11561: Fixed default Kerberos configuration allowing privilege escalation on AD-joined Linux systems (bsc#1244325) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-119=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-119=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libipa_hbac-devel-2.9.5-160000.3.1 * libsss_idmap-devel-2.9.5-160000.3.1 * libipa_hbac0-debuginfo-2.9.5-160000.3.1 * sssd-ipa-debuginfo-2.9.5-160000.3.1 * sssd-ad-2.9.5-160000.3.1 * libsss_certmap0-2.9.5-160000.3.1 * libipa_hbac0-2.9.5-160000.3.1 * sssd-krb5-common-2.9.5-160000.3.1 * sssd-ldap-2.9.5-160000.3.1 * sssd-tools-debuginfo-2.9.5-160000.3.1 * libsss_nss_idmap0-debuginfo-2.9.5-160000.3.1 * libsss_certmap0-debuginfo-2.9.5-160000.3.1 * python3-sssd-config-2.9.5-160000.3.1 * sssd-krb5-2.9.5-160000.3.1 *sssd-proxy-2.9.5-160000.3.1 * sssd-ipa-2.9.5-160000.3.1 * sssd-kcm-debuginfo-2.9.5-160000.3.1 * sssd-krb5-common-debuginfo-2.9.5-160000.3.1 * python3-ipa_hbac-debuginfo-2.9.5-160000.3.1 * sssd-debugsource-2.9.5-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.9.5-160000.3.1 * sssd-winbind-idmap-2.9.5-160000.3.1 * libnfsidmap-sss-debuginfo-2.9.5-160000.3.1 * sssd-ad-debuginfo-2.9.5-160000.3.1 * libsss_idmap0-2.9.5-160000.3.1 * libsss_nss_idmap0-2.9.5-160000.3.1 * sssd-ldap-debuginfo-2.9.5-160000.3.1 * sssd-debuginfo-2.9.5-160000.3.1 * python3-sss-murmur-2.9.5-160000.3.1 * sssd-winbind-idmap-debuginfo-2.9.5-160000.3.1 * libnfsidmap-sss-2.9.5-160000.3.1 * libsss_nss_idmap-devel-2.9.5-160000.3.1 * libsss_idmap0-debuginfo-2.9.5-160000.3.1 * python3-sss_nss_idmap-2.9.5-160000.3.1 * libsss_certmap-devel-2.9.5-160000.3.1 * sssd-2.9.5-160000.3.1 * python3-sss-murmur-debuginfo-2.9.5-160000.3.1 * sssd-dbus-2.9.5-160000.3.1 * sssd-proxy-debuginfo-2.9.5-160000.3.1 * sssd-krb5-debuginfo-2.9.5-160000.3.1 * sssd-kcm-2.9.5-160000.3.1 * sssd-dbus-debuginfo-2.9.5-160000.3.1 * python3-ipa_hbac-2.9.5-160000.3.1 * sssd-tools-2.9.5-160000.3.1 * python3-sssd-config-debuginfo-2.9.5-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * libipa_hbac-devel-2.9.5-160000.3.1 * libsss_idmap-devel-2.9.5-160000.3.1 * libipa_hbac0-debuginfo-2.9.5-160000.3.1 * sssd-ipa-debuginfo-2.9.5-160000.3.1 * sssd-ad-2.9.5-160000.3.1 * libsss_certmap0-2.9.5-160000.3.1 * libipa_hbac0-2.9.5-160000.3.1 * sssd-krb5-common-2.9.5-160000.3.1 * sssd-ldap-2.9.5-160000.3.1 * sssd-tools-debuginfo-2.9.5-160000.3.1 * libsss_nss_idmap0-debuginfo-2.9.5-160000.3.1 * libsss_certmap0-debuginfo-2.9.5-160000.3.1 * python3-sssd-config-2.9.5-160000.3.1 * sssd-krb5-2.9.5-160000.3.1 * sssd-proxy-2.9.5-160000.3.1 * sssd-ipa-2.9.5-160000.3.1 *sssd-kcm-debuginfo-2.9.5-160000.3.1 * sssd-krb5-common-debuginfo-2.9.5-160000.3.1 * python3-ipa_hbac-debuginfo-2.9.5-160000.3.1 * sssd-debugsource-2.9.5-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.9.5-160000.3.1 * sssd-winbind-idmap-2.9.5-160000.3.1 * libnfsidmap-sss-debuginfo-2.9.5-160000.3.1 * sssd-ad-debuginfo-2.9.5-160000.3.1 * libsss_idmap0-2.9.5-160000.3.1 * libsss_nss_idmap0-2.9.5-160000.3.1 * sssd-ldap-debuginfo-2.9.5-160000.3.1 * sssd-debuginfo-2.9.5-160000.3.1 * python3-sss-murmur-2.9.5-160000.3.1 * sssd-winbind-idmap-debuginfo-2.9.5-160000.3.1 * libnfsidmap-sss-2.9.5-160000.3.1 * libsss_nss_idmap-devel-2.9.5-160000.3.1 * libsss_idmap0-debuginfo-2.9.5-160000.3.1 * python3-sss_nss_idmap-2.9.5-160000.3.1 * libsss_certmap-devel-2.9.5-160000.3.1 * sssd-2.9.5-160000.3.1 * python3-sss-murmur-debuginfo-2.9.5-160000.3.1 * sssd-dbus-2.9.5-160000.3.1 * sssd-proxy-debuginfo-2.9.5-160000.3.1 * sssd-krb5-debuginfo-2.9.5-160000.3.1 * sssd-kcm-2.9.5-160000.3.1 * sssd-dbus-debuginfo-2.9.5-160000.3.1 * python3-ipa_hbac-2.9.5-160000.3.1 * sssd-tools-2.9.5-160000.3.1 * python3-sssd-config-debuginfo-2.9.5-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11561.html * https://bugzilla.suse.com/show_bug.cgi?id=1244325 * https://bugzilla.suse.com/show_bug.cgi?id=1251827 . Discover a security update for SUSE addressing an important privilege escalation issue in sssd software. Update now!. SUSE security advisory, sssd update, privilege escalation fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for sssd Announcement ID: SUSE-SU-2026:20014-1 Release Date: 2026-01-02T16:58:31Z Rating: important References: * bsc#1244325 * bsc#1251827 Cross-References: * CVE-2025-11561 CVSS scores: * CVE-2025-11561 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-11561 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11561 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for sssd fixes the following issues: * CVE-2025-11561: Fixed default Kerberos configuration allowing privilege escalation on AD-joined Linux systems (bsc#1244325) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-119=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * sssd-ad-2.9.5-160000.3.1 * libsss_certmap0-2.9.5-160000.3.1 * sssd-krb5-common-2.9.5-160000.3.1 * sssd-ldap-2.9.5-160000.3.1 * sssd-tools-debuginfo-2.9.5-160000.3.1 * python3-sssd-config-2.9.5-160000.3.1 * libsss_certmap0-debuginfo-2.9.5-160000.3.1 * sssd-krb5-2.9.5-160000.3.1 * sssd-krb5-common-debuginfo-2.9.5-160000.3.1 * sssd-debugsource-2.9.5-160000.3.1 * sssd-ad-debuginfo-2.9.5-160000.3.1 * libsss_idmap0-2.9.5-160000.3.1 * sssd-ldap-debuginfo-2.9.5-160000.3.1 * sssd-debuginfo-2.9.5-160000.3.1 * libsss_idmap0-debuginfo-2.9.5-160000.3.1 * sssd-2.9.5-160000.3.1 * sssd-dbus-2.9.5-160000.3.1 * sssd-krb5-debuginfo-2.9.5-160000.3.1 * sssd-dbus-debuginfo-2.9.5-160000.3.1 *sssd-tools-2.9.5-160000.3.1 * python3-sssd-config-debuginfo-2.9.5-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11561.html * https://bugzilla.suse.com/show_bug.cgi?id=1244325 * https://bugzilla.suse.com/show_bug.cgi?id=1251827 . A security update for SUSE addresses a critical issue in sssd, resolving privilege escalation vulnerabilities.. sssd security update, SUSE Linux Micro threat, privilege escalation fix, sssd vulnerability management. . Severity: Important. LinuxSecurity.com Team
* bsc#1244325 * bsc#1251827 Cross-References: * CVE-2025-11561 . # Security update for sssd Announcement ID: SUSE-SU-2025:21084-1 Release Date: 2025-11-27T11:12:20Z Rating: important References: * bsc#1244325 * bsc#1251827 Cross-References: * CVE-2025-11561 CVSS scores: * CVE-2025-11561 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-11561 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11561 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for sssd fixes the following issues: * CVE-2025-11561: Fixed default Kerberos configuration allowing privilege escalation on AD-joined Linux systems (bsc#1251827) Other fixes: \- Install file in krb5.conf.d to include sssd krb5 config snippets (bsc#1244325) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-527=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * sssd-ad-debuginfo-2.8.2-7.1 * libsss_nss_idmap0-debuginfo-2.8.2-7.1 * libsss_idmap0-2.8.2-7.1 * sssd-krb5-debuginfo-2.8.2-7.1 * libsss_nss_idmap0-2.8.2-7.1 * python3-sssd-config-2.8.2-7.1 * sssd-ldap-debuginfo-2.8.2-7.1 * python3-sssd-config-debuginfo-2.8.2-7.1 * sssd-ad-2.8.2-7.1 * sssd-krb5-common-debuginfo-2.8.2-7.1 * sssd-dbus-debuginfo-2.8.2-7.1 * sssd-krb5-common-2.8.2-7.1 * libsss_certmap0-2.8.2-7.1 * libsss_idmap0-debuginfo-2.8.2-7.1 * sssd-krb5-2.8.2-7.1 * sssd-dbus-2.8.2-7.1 * libsss_certmap0-debuginfo-2.8.2-7.1 * sssd-debuginfo-2.8.2-7.1 * sssd-2.8.2-7.1 * sssd-debugsource-2.8.2-7.1 * sssd-ldap-2.8.2-7.1 * sssd-tools-2.8.2-7.1 * sssd-tools-debuginfo-2.8.2-7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11561.html * https://bugzilla.suse.com/show_bug.cgi?id=1244325 * https://bugzilla.suse.com/show_bug.cgi?id=1251827 . SUSE's critical sssd update addresses privilege escalation and important fixes for system security. Essential for AD-connected systems.. sssd security update, SUSE Linux Micro patch, privileged access control, security advisory details. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.