<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:49:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:3151 — Important: sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:3151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libsss_nss_idmap-devel&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: shell command injection in sssctl (CVE-2021-3621)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libsss_nss_idmap-devel&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: shell command injection in sssctl (CVE-2021-3621)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:3151</guid>
    </item>
    <item>
      <title>bdu:2023-07637</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07637</link>
      <description>bdu:2023-07637</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07637</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0051 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0051</link>
      <description>certfr-2023-avi-0051</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0051</guid>
    </item>
    <item>
      <title>EUVD-2026-258006</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258006</link>
      <description>EUVD-2026-258006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258006</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3621</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3621</link>
      <description>&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3621</guid>
    </item>
    <item>
      <title>GHSA-g527-g4q2-57xc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g527-g4q2-57xc</link>
      <description>&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g527-g4q2-57xc</guid>
    </item>
    <item>
      <title>gsd-2021-3621</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3621</link>
      <description>gsd-2021-3621</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3621</guid>
    </item>
    <item>
      <title>OESA-2021-1340 — sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1340</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: sssd, openEuler:20.03-LTS-SP2: sssd&lt;/p&gt;
&lt;p&gt;SSSD provides a set of daemons to manage access to remote directories and authentication mechanisms such as LDAP, Kerberos or FreeIPA. It provides an NSS and PAM interface toward the system and a pluggable backend system to connect to multiple different account sources.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3621)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: sssd, openEuler:20.03-LTS-SP2: sssd&lt;/p&gt;
&lt;p&gt;SSSD provides a set of daemons to manage access to remote directories and authentication mechanisms such as LDAP, Kerberos or FreeIPA. It provides an NSS and PAM interface toward the system and a pluggable backend system to connect to multiple different account sources.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3621)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1340</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:2941-1 — Security update for sssd</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2941-1</link>
      <description>&lt;p&gt;Security update for sssd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sssd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:2941-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3178 — Red Hat Security Advisory: sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3178</link>
      <description>&lt;p&gt;sssd: shell command injection in sssctl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sssd: shell command injection in sssctl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3178</guid>
    </item>
    <item>
      <title>SUSE-RU-2021:3185-1 — Recommended update for sssd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2021:3185-1</link>
      <description>&lt;p&gt;Recommended update for sssd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for sssd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2021:3185-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3621</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3621</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: sssd, Ubuntu:20.04:LTS: sssd, Ubuntu:22.04:LTS: sssd&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: sssd, Ubuntu:20.04:LTS: sssd, Ubuntu:22.04:LTS: sssd&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3621</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1001 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1001</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1001</guid>
    </item>
  </channel>
</rss>
