Описание
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
Отчет
Red Hat has rated this as Important because the attack requires only low-privilege delegated LDAP write access to any subtree, which is a common delegation pattern in enterprise environments. The default ldap_sudo_search_base configuration searches the entire directory tree, allowing sudo rule injection from outside the intended sudoers container.
Меры по смягчению последствий
Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | sssd | Out of support scope | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | ||
| Red Hat Enterprise Linux 10 | sssd | Fixed | RHSA-2026:41937 | 20.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | sssd | Fixed | RHSA-2026:46482 | 27.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | sssd | Fixed | RHSA-2026:50109 | 04.08.2026 |
| Red Hat Enterprise Linux 8 | sssd | Fixed | RHSA-2026:46990 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | sssd | Fixed | RHSA-2026:46990 | 28.07.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | sssd | Fixed | RHSA-2026:49841 | 04.08.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | sssd | Fixed | RHSA-2026:49841 | 04.08.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | sssd | Fixed | RHSA-2026:49844 | 04.08.2026 |
Показывать по
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
8.8 High
CVSS3