Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3899-1

Опубликовано: 31 авг. 2026
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issues:

  • CVE-2026-68742: unvalidated address lengths in NSS responder packet parsing can cause a heap out-of-bounds read (bsc#1273922).
  • CVE-2026-68743: oversized length parameters in authentication requests can cause heap out-of-bounds reads (bsc#1273925).
  • CVE-2026-68744: unshrunk packet allocations during group resolution can allow uninitialized heap memory disclosure (bsc#1273924).

Changes for sssd:

  • Warn about ldap_sudo_search_base only if sudo target is enabled; (bsc#1273009)

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
libipa_hbac-devel-2.10.2-150700.9.40.1
libipa_hbac0-2.10.2-150700.9.40.1
libsss_certmap-devel-2.10.2-150700.9.40.1
libsss_certmap0-2.10.2-150700.9.40.1
libsss_idmap-devel-2.10.2-150700.9.40.1
libsss_idmap0-2.10.2-150700.9.40.1
libsss_nss_idmap-devel-2.10.2-150700.9.40.1
libsss_nss_idmap0-2.10.2-150700.9.40.1
libsss_simpleifp-devel-2.10.2-150700.9.40.1
libsss_simpleifp0-2.10.2-150700.9.40.1
python3-sssd-config-2.10.2-150700.9.40.1
sssd-2.10.2-150700.9.40.1
sssd-32bit-2.10.2-150700.9.40.1
sssd-ad-2.10.2-150700.9.40.1
sssd-dbus-2.10.2-150700.9.40.1
sssd-ipa-2.10.2-150700.9.40.1
sssd-kcm-2.10.2-150700.9.40.1
sssd-krb5-2.10.2-150700.9.40.1
sssd-krb5-common-2.10.2-150700.9.40.1
sssd-ldap-2.10.2-150700.9.40.1
sssd-proxy-2.10.2-150700.9.40.1
sssd-tools-2.10.2-150700.9.40.1
sssd-winbind-idmap-2.10.2-150700.9.40.1

Описание

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac0-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap0-2.10.2-150700.9.40.1

Ссылки

Описание

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac0-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap0-2.10.2-150700.9.40.1

Ссылки

Описание

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libipa_hbac0-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap-devel-2.10.2-150700.9.40.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libsss_certmap0-2.10.2-150700.9.40.1

Ссылки