Описание
Security update for sssd
This update for sssd fixes the following issue:
- CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807).
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libipa_hbac-devel-1.16.1-7.76.1
libipa_hbac0-1.16.1-7.76.1
libsss_certmap0-1.16.1-7.76.1
libsss_idmap-devel-1.16.1-7.76.1
libsss_idmap0-1.16.1-7.76.1
libsss_nss_idmap-devel-1.16.1-7.76.1
libsss_nss_idmap0-1.16.1-7.76.1
libsss_simpleifp0-1.16.1-7.76.1
python-sssd-config-1.16.1-7.76.1
sssd-1.16.1-7.76.1
sssd-ad-1.16.1-7.76.1
sssd-common-1.16.1-7.76.1
sssd-common-32bit-1.16.1-7.76.1
sssd-dbus-1.16.1-7.76.1
sssd-ipa-1.16.1-7.76.1
sssd-krb5-1.16.1-7.76.1
sssd-krb5-common-1.16.1-7.76.1
sssd-ldap-1.16.1-7.76.1
sssd-proxy-1.16.1-7.76.1
sssd-tools-1.16.1-7.76.1
Ссылки
- Link for SUSE-SU-2026:3394-1
- E-Mail link for SUSE-SU-2026:3394-1
- SUSE Security Ratings
- SUSE Bug 1269807
- SUSE CVE CVE-2026-12610 page
Описание
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libipa_hbac-devel-1.16.1-7.76.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libipa_hbac0-1.16.1-7.76.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libsss_certmap0-1.16.1-7.76.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libsss_idmap-devel-1.16.1-7.76.1
Ссылки
- CVE-2026-12610
- SUSE Bug 1269807