Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-19851

Опубликовано: 06 нояб. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-19851: sssd security update (IMPORTANT)

[2.10.2-3.0.1.3]

  • Restore default debug level for sss_cache [Orabug: 32810448]

[2.10.2-3.3]

  • Resolves: RHEL-120286 - CVE-2025-11561 sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems [rhel-10.0.z]

[2.10.2-3.2]

  • Resolves: RHEL-79158 - Disk cache failure with large db sizes

[2.10.2-3.1]

  • Resolves: RHEL-79158 - Disk cache failure with large db sizes

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

sssd-idp

2.10.2-3.0.1.el10_0.3

libipa_hbac

2.10.2-3.0.1.el10_0.3

libsss_autofs

2.10.2-3.0.1.el10_0.3

libsss_certmap

2.10.2-3.0.1.el10_0.3

libsss_idmap

2.10.2-3.0.1.el10_0.3

libsss_nss_idmap

2.10.2-3.0.1.el10_0.3

libsss_sudo

2.10.2-3.0.1.el10_0.3

python3-libipa_hbac

2.10.2-3.0.1.el10_0.3

python3-libsss_nss_idmap

2.10.2-3.0.1.el10_0.3

python3-sss

2.10.2-3.0.1.el10_0.3

python3-sss-murmur

2.10.2-3.0.1.el10_0.3

python3-sssdconfig

2.10.2-3.0.1.el10_0.3

sssd

2.10.2-3.0.1.el10_0.3

sssd-ad

2.10.2-3.0.1.el10_0.3

sssd-client

2.10.2-3.0.1.el10_0.3

sssd-common

2.10.2-3.0.1.el10_0.3

sssd-common-pac

2.10.2-3.0.1.el10_0.3

sssd-dbus

2.10.2-3.0.1.el10_0.3

sssd-ipa

2.10.2-3.0.1.el10_0.3

sssd-kcm

2.10.2-3.0.1.el10_0.3

sssd-krb5

2.10.2-3.0.1.el10_0.3

sssd-krb5-common

2.10.2-3.0.1.el10_0.3

sssd-ldap

2.10.2-3.0.1.el10_0.3

sssd-nfs-idmap

2.10.2-3.0.1.el10_0.3

sssd-passkey

2.10.2-3.0.1.el10_0.3

sssd-proxy

2.10.2-3.0.1.el10_0.3

sssd-tools

2.10.2-3.0.1.el10_0.3

sssd-winbind-idmap

2.10.2-3.0.1.el10_0.3

libsss_nss_idmap-devel

2.10.2-3.0.1.el10_0.3

Oracle Linux x86_64

libipa_hbac

2.10.2-3.0.1.el10_0.3

libsss_idmap

2.10.2-3.0.1.el10_0.3

libsss_nss_idmap

2.10.2-3.0.1.el10_0.3

libsss_sudo

2.10.2-3.0.1.el10_0.3

python3-libipa_hbac

2.10.2-3.0.1.el10_0.3

python3-libsss_nss_idmap

2.10.2-3.0.1.el10_0.3

python3-sss

2.10.2-3.0.1.el10_0.3

python3-sss-murmur

2.10.2-3.0.1.el10_0.3

python3-sssdconfig

2.10.2-3.0.1.el10_0.3

sssd

2.10.2-3.0.1.el10_0.3

sssd-ad

2.10.2-3.0.1.el10_0.3

sssd-client

2.10.2-3.0.1.el10_0.3

sssd-common

2.10.2-3.0.1.el10_0.3

sssd-common-pac

2.10.2-3.0.1.el10_0.3

sssd-ipa

2.10.2-3.0.1.el10_0.3

sssd-kcm

2.10.2-3.0.1.el10_0.3

sssd-krb5-common

2.10.2-3.0.1.el10_0.3

sssd-ldap

2.10.2-3.0.1.el10_0.3

sssd-nfs-idmap

2.10.2-3.0.1.el10_0.3

sssd-passkey

2.10.2-3.0.1.el10_0.3

sssd-proxy

2.10.2-3.0.1.el10_0.3

sssd-tools

2.10.2-3.0.1.el10_0.3

sssd-winbind-idmap

2.10.2-3.0.1.el10_0.3

sssd-idp

2.10.2-3.0.1.el10_0.3

libsss_autofs

2.10.2-3.0.1.el10_0.3

libsss_certmap

2.10.2-3.0.1.el10_0.3

sssd-dbus

2.10.2-3.0.1.el10_0.3

sssd-krb5

2.10.2-3.0.1.el10_0.3

libsss_nss_idmap-devel

2.10.2-3.0.1.el10_0.3

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
nvd
4 месяца назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
debian
4 месяца назад

A flaw was found in the integration of Active Directory and the System ...

suse-cvrf
около 1 месяца назад

Security update for sssd

suse-cvrf
2 месяца назад

Security update for sssd