Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:2571

Опубликовано: 10 мая 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: sssd security and bug fix update

The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.

Security Fix(es):

  • sssd: Race condition during authorization leads to GPO policies functioning inconsistently (CVE-2023-3758)

Bug Fix(es):

  • socket leak (JIRA:Rocky Linux-22340)

  • Passkey cannot fall back to password (JIRA:Rocky Linux-28161)

  • sssd: Race condition during authorization leads to GPO policies functioning inconsistently (JIRA:Rocky Linux-27209)

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
sssd-idpaarch646.el9_4sssd-idp-2.9.4-6.el9_4.aarch64.rpm
sssd-idpx86_646.el9_4sssd-idp-2.9.4-6.el9_4.x86_64.rpm
libipa_hbacaarch646.el9_4libipa_hbac-2.9.4-6.el9_4.aarch64.rpm
libsss_autofsaarch646.el9_4libsss_autofs-2.9.4-6.el9_4.aarch64.rpm
libsss_certmapaarch646.el9_4libsss_certmap-2.9.4-6.el9_4.aarch64.rpm
libsss_idmapaarch646.el9_4libsss_idmap-2.9.4-6.el9_4.aarch64.rpm
libsss_nss_idmapaarch646.el9_4libsss_nss_idmap-2.9.4-6.el9_4.aarch64.rpm
libsss_simpleifpaarch646.el9_4libsss_simpleifp-2.9.4-6.el9_4.aarch64.rpm
libsss_sudoaarch646.el9_4libsss_sudo-2.9.4-6.el9_4.aarch64.rpm
python3-libipa_hbacaarch646.el9_4python3-libipa_hbac-2.9.4-6.el9_4.aarch64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
redhat
больше 2 лет назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
nvd
больше 2 лет назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
debian
больше 2 лет назад

A race condition flaw was found in sssd where the GPO policy is not co ...

suse-cvrf
около 2 лет назад

Security update for sssd