Synopsis:
sssd security updateSummary:
An update for sssd is now available for openEuler-24.03-LTS-SP1Description:
Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA.
Security Fix(es):
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.(CVE-2026-14474)Topic:
An update for sssd is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
HighAffected Component:
sssd
2.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp12.9.4-22.oe2403sp1Exploitability
AV:NAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:H8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H