RHSA-2026:49839HighCVSS 8.8

Red Hat Security Advisory: sssd security update

Published
August 4, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-14474 — sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation CVE-2026-14476 — sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass

🎯 Affected products200

  • Red Hat CodeReady Linux Builder EUS (v.9.6)
  • Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-0:2.9.6-4.el9_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-0:2.9.6-4.el9_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-0:2.9.6-4.el9_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-0:2.9.6-4.el9_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • libipa_hbac-debuginfo-0:2.9.6-4.el9_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-0:2.9.6-4.el9_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-0:2.9.6-4.el9_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-0:2.9.6-4.el9_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • libsss_autofs-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • libsss_autofs-debuginfo-0:2.9.6-4.el9_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • libsss_autofs-debuginfo-0:2.9.6-4.el9_6.5.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container. Workaround: Set ad_gpo_access_control = disabled in /etc/sssd/sssd.conf to disable GPO fetching entirely. Note that this removes GPO-based login policy enforcement.

🔗 References (5)