Red Hat Security Advisory: sssd security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-14474 — sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation CVE-2026-14476 — sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
🎯 Affected products186
- Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libipa_hbac-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libipa_hbac-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libipa_hbac-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libipa_hbac-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libipa_hbac-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libipa_hbac-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libipa_hbac-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libipa_hbac-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_autofs-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_autofs-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_autofs-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_autofs-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_autofs-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_autofs-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_certmap-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_certmap-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_certmap-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_certmap-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_certmap-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_certmap-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_certmap-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_certmap-debuginfo-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_idmap-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_idmap-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_idmap-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_idmap-0:2.4.0-9.el8_4.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- libsss_idmap-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- libsss_idmap-debuginfo-0:2.4.0-9.el8_4.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- +156 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container. Workaround: Set ad_gpo_access_control = disabled in /etc/sssd/sssd.conf to disable GPO fetching entirely. Note that this removes GPO-based login policy enforcement.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:49841
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2496556
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2496581
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49841.json