Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3797-1

Опубликовано: 25 авг. 2026
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issue:

  • CVE-2026-68743: insufficient validation in the PAM responder can lead to an out-of-bounds read and a process crash when a crafted protocol v1 request is processed (bsc#1273925).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libipa_hbac-devel-1.16.1-7.79.1
libipa_hbac0-1.16.1-7.79.1
libsss_certmap0-1.16.1-7.79.1
libsss_idmap-devel-1.16.1-7.79.1
libsss_idmap0-1.16.1-7.79.1
libsss_nss_idmap-devel-1.16.1-7.79.1
libsss_nss_idmap0-1.16.1-7.79.1
libsss_simpleifp0-1.16.1-7.79.1
python-sssd-config-1.16.1-7.79.1
sssd-1.16.1-7.79.1
sssd-ad-1.16.1-7.79.1
sssd-common-1.16.1-7.79.1
sssd-common-32bit-1.16.1-7.79.1
sssd-dbus-1.16.1-7.79.1
sssd-ipa-1.16.1-7.79.1
sssd-krb5-1.16.1-7.79.1
sssd-krb5-common-1.16.1-7.79.1
sssd-ldap-1.16.1-7.79.1
sssd-proxy-1.16.1-7.79.1
sssd-tools-1.16.1-7.79.1

Описание

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libipa_hbac-devel-1.16.1-7.79.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libipa_hbac0-1.16.1-7.79.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libsss_certmap0-1.16.1-7.79.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libsss_idmap-devel-1.16.1-7.79.1

Ссылки