Your message dated Fri, 04 Sep 2026 21:16:31 +0000
with message-id <[email protected]>
and subject line Bug#1141769: fixed in sssd 2.13.1-1
has caused the Debian Bug report #1141769,
regarding sssd: CVE-2026-14474 CVE-2026-14476
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141769: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141769
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: sssd
Version: 2.12.0-4
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for sssd.
CVE-2026-14474[0]:
| A flaw was found in SSSD's LDAP sudo provider. When the
| ldap_sudo_search_base option is not explicitly configured, SSSD
| searches the entire LDAP directory tree for sudoRole objects. An
| authenticated attacker with write access to any subtree can inject a
| sudoRole object granting root-level sudo privileges on all SSSD-
| enrolled hosts.
CVE-2026-14476[1]:
| A path traversal flaw was found in SSSD's AD GPO provider. The
| ad_gpo_extract_smb_components() function does not sanitize ..
| sequences in the gPCFileSysPath LDAP attribute, allowing an attacker
| with AD GPO management access to write files outside the GPO cache
| directory as root. On default RHEL configurations with SELinux
| enforcing, this can be used to inject Kerberos configuration leading
| to authentication bypass.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-14474
https://www.cve.org/CVERecord?id=CVE-2026-14474
[1] https://security-tracker.debian.org/tracker/CVE-2026-14476
https://www.cve.org/CVERecord?id=CVE-2026-14476
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: sssd
Source-Version: 2.13.1-1
Done: Mike Gabriel <[email protected]>
We believe that the bug you reported is fixed in the latest version of
sssd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mike Gabriel <[email protected]> (supplier of updated sssd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 03 Sep 2026 12:16:27 +0200
Source: sssd
Architecture: source
Version: 2.13.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian SSSD Team <[email protected]>
Changed-By: Mike Gabriel <[email protected]>
Closes: 1134269 1141323 1141769
Changes:
sssd (2.13.1-1) unstable; urgency=medium
.
* Team upload.
.
[ Timo Aaltonen ]
* New upstream release.
- CVE-2026-6245: pam: fix out-of-bounds read in
pam_passkey_child_read_data.
(Closes: #1134269).
* patches: Drop upstreamed patch.
* source: Update diff-ignore.
* control: Change maintainer address.
.
[ Mike Gabriel ]
* debian/patches:
+ Update fix-whitespace-test.diff. Add logic to ignore various code files
during the whitespace tests
+ Add fix-ftbfs-src-m4.patch. Fix FTBFS due to missing src/m4 Makefile
target.
+ Add fix-underlinking-keyutils.patch. Assure that unit tests that
reference
headers from libkeyutils-dev get linked against the library.
+ Add fix-eol-flaws-in-codefiles.patch. Fix EOL and EOF issue in one file
to
make whitespace_test unit test happy.
+ CVE-2026-12610: Add CVE-2026-12610.diff. PAM: fix use-after-free during
p11_child processing. (Closes: #1141323).
+ CVE-2026-14474, CVE-2026-14476: Add CVE-2026-14474.diff (sudo: warn when
ldap_sudo_search_base falls back to root DN) and CVE-2026-14476.diff
(gpo:
reject path traversal in gPCFileSysPath. (Closes: #1141769).
Checksums-Sha1:
e5d89185a6a6c43c8b1077bbc8532900769f57d6 5165 sssd_2.13.1-1.dsc
d4510a8875a5183e2d1cbea8b24b35e984959e05 9136618 sssd_2.13.1.orig.tar.gz
92f49083de70833ade28ca7df834dfbb5b0236ec 833 sssd_2.13.1.orig.tar.gz.asc
a981092002c731374610204bda13674acab0a3c9 53120 sssd_2.13.1-1.debian.tar.xz
58f1e29b1174c0931b1e507f8b4edb63714382c3 19490 sssd_2.13.1-1_source.buildinfo
Checksums-Sha256:
0109edd80074c9ab53a85f6d76d6de92762ab2ddcab7ce6d508eb4f53d712518 5165
sssd_2.13.1-1.dsc
05ea79e89f0be399983925b8874ac196d6dc5fd4416f83609557b9fc8ef798b5 9136618
sssd_2.13.1.orig.tar.gz
aa199860656563065819cedd3aa0b217ae6ce357a6c2c3311ba0b68fcb9cdcab 833
sssd_2.13.1.orig.tar.gz.asc
e4dde2863bf4d7c2017cf7142a16bda3059d501720ad4143961f941a57ae0eb8 53120
sssd_2.13.1-1.debian.tar.xz
26f73d73706a240dfad2ec4425d34314b7d5d2a54dbaa9e4c3dc63d6af7d8eb5 19490
sssd_2.13.1-1_source.buildinfo
Files:
b933a4c0017e1657c0c672e769ab1dbc 5165 utils optional sssd_2.13.1-1.dsc
f5e1d4554e28560059b4ffd551a668d9 9136618 utils optional sssd_2.13.1.orig.tar.gz
a08da1bfe5734a8d103c55134e2909b7 833 utils optional sssd_2.13.1.orig.tar.gz.asc
0ba01f5cce64c2b1a0de4bc84a9eadc6 53120 utils optional
sssd_2.13.1-1.debian.tar.xz
ff09e976b315b02c36984f1072d6a7bd 19490 utils optional
sssd_2.13.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJJBAEBCgAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmqZTFYVHHN1bndlYXZl
ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxZLQP/jjd6uICH8BE7JZjDbZJrS1OqzFI
JWq+bzHfbKwz910d4FmIop/aY7dp3+n8Nenih0wYvuDzxqdQgEyjwAiY5ua8vp9a
D2T2PO/4JZLoF2vABv54q4ztt7Tm501ho73jrR8mMcO7z88/f+W2KXMNY1Ok3ybp
0/eQiNrR5gOHbDoQI23AjcRBdCuRwOYvuLnp0rM09rVTK8rLYWQI7dBbOrfzf+DY
VaagIoytr3C/mXBNbyHJg875qdzZ88dyI90otxRfBLW7nupK9EMkA8CRM3wtnsKP
SpmyirxpsNXhnbj3601eUw8CTdYh/bBGLTou4o0eS3gAiM9+PNGLdlsePFadxZYG
YWGoz3EjJkGzASbTBVIn5Ebap1KW5st5WqMUKZGBFPyVivHTJiuujst1bvhrdO2J
XQMa7CxPG0IuXQWqwE/VV7821LMSVPxmh2qb0T2b/SFa8pW7jnocuiCb0QCU7CJ2
4RcV1vWtGIMUGULOpxKza96e1Vzzp//cR5rcbzJ0fJ8CqVRfITD9G6hnXqxxd+uJ
B3b5H8cgstTn2by7Gn+tPgijU5RbvsloQLwyy6STWcLwZc+eGDbrMj7P85m0MgVD
GlMG6/9x6uhBLg3Uc/C51D+edpq0wk+enLv0Fn/9sDVAP5S7H1W0bp6YvjwOYN2G
rVQxeWS9ImYHW3Kb
=Z886
-----END PGP SIGNATURE-----
pgp8Fn3aMG7AF.pgp
Description: PGP signature
--- End Message ---