Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:19610

Опубликовано: 05 нояб. 2025
Источник: rocky
Оценка: Important

Описание

Important: sssd security update

The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.

Security Fix(es):

  • sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems (CVE-2025-11561)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libipa_hbaci6865.el8_10.3libipa_hbac-2.9.4-5.el8_10.3.i686.rpm
libipa_hbacx86_645.el8_10.3libipa_hbac-2.9.4-5.el8_10.3.x86_64.rpm
libsss_autofsx86_645.el8_10.3libsss_autofs-2.9.4-5.el8_10.3.x86_64.rpm
libsss_certmapi6865.el8_10.3libsss_certmap-2.9.4-5.el8_10.3.i686.rpm
libsss_certmapx86_645.el8_10.3libsss_certmap-2.9.4-5.el8_10.3.x86_64.rpm
libsss_idmapi6865.el8_10.3libsss_idmap-2.9.4-5.el8_10.3.i686.rpm
libsss_idmapx86_645.el8_10.3libsss_idmap-2.9.4-5.el8_10.3.x86_64.rpm
libsss_nss_idmapi6865.el8_10.3libsss_nss_idmap-2.9.4-5.el8_10.3.i686.rpm
libsss_nss_idmapx86_645.el8_10.3libsss_nss_idmap-2.9.4-5.el8_10.3.x86_64.rpm
libsss_simpleifpi6865.el8_10.3libsss_simpleifp-2.9.4-5.el8_10.3.i686.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
nvd
4 месяца назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
debian
4 месяца назад

A flaw was found in the integration of Active Directory and the System ...

suse-cvrf
около 1 месяца назад

Security update for sssd

suse-cvrf
2 месяца назад

Security update for sssd