RHSA-2026:50109HighCVSS 8.8

Red Hat Security Advisory: sssd security update

Published
August 4, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-14474 — sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation CVE-2026-14476 — sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass

🎯 Affected products186

  • Red Hat Enterprise Linux Server (v. 7 ELS)
  • Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-0:1.16.5-10.el7_9.18.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.ppc as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.s390 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libipa_hbac-devel-0:1.16.5-10.el7_9.18.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libsss_autofs-0:1.16.5-10.el7_9.18.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_autofs-0:1.16.5-10.el7_9.18.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_autofs-0:1.16.5-10.el7_9.18.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_autofs-0:1.16.5-10.el7_9.18.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-0:1.16.5-10.el7_9.18.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • libsss_certmap-devel-0:1.16.5-10.el7_9.18.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libsss_certmap-devel-0:1.16.5-10.el7_9.18.ppc as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • libsss_certmap-devel-0:1.16.5-10.el7_9.18.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
  • +156 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container. Workaround: Set ad_gpo_access_control = disabled in /etc/sssd/sssd.conf to disable GPO fetching entirely. Note that this removes GPO-based login policy enforcement.

🔗 References (5)