Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3401-1

Опубликовано: 29 июл. 2026
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issue:

  • CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
libipa_hbac-devel-2.10.2-150700.9.37.1
libipa_hbac0-2.10.2-150700.9.37.1
libsss_certmap-devel-2.10.2-150700.9.37.1
libsss_certmap0-2.10.2-150700.9.37.1
libsss_idmap-devel-2.10.2-150700.9.37.1
libsss_idmap0-2.10.2-150700.9.37.1
libsss_nss_idmap-devel-2.10.2-150700.9.37.1
libsss_nss_idmap0-2.10.2-150700.9.37.1
libsss_simpleifp-devel-2.10.2-150700.9.37.1
libsss_simpleifp0-2.10.2-150700.9.37.1
python3-sssd-config-2.10.2-150700.9.37.1
sssd-2.10.2-150700.9.37.1
sssd-32bit-2.10.2-150700.9.37.1
sssd-ad-2.10.2-150700.9.37.1
sssd-dbus-2.10.2-150700.9.37.1
sssd-ipa-2.10.2-150700.9.37.1
sssd-kcm-2.10.2-150700.9.37.1
sssd-krb5-2.10.2-150700.9.37.1
sssd-krb5-common-2.10.2-150700.9.37.1
sssd-ldap-2.10.2-150700.9.37.1
sssd-proxy-2.10.2-150700.9.37.1
sssd-tools-2.10.2-150700.9.37.1
sssd-winbind-idmap-2.10.2-150700.9.37.1

Описание

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac-devel-2.10.2-150700.9.37.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac0-2.10.2-150700.9.37.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap-devel-2.10.2-150700.9.37.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap0-2.10.2-150700.9.37.1

Ссылки
Уязвимость SUSE-SU-2026:3401-1