<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:16:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:41937 — Important: sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:41937</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libipa_hbac, AlmaLinux:10: libsss_autofs, AlmaLinux:10: libsss_certmap, AlmaLinux:10: libsss_idmap, AlmaLinux:10: libsss_nss_idmap, AlmaLinux:10: libsss_nss_idmap-devel, AlmaLinux:10: libsss_sudo, AlmaLinux:10: python3-libipa_hbac, AlmaLinux:10: python3-libsss_nss_idmap, AlmaLinux:10: python3-sss and 19 more&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474)
  * sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libipa_hbac, AlmaLinux:10: libsss_autofs, AlmaLinux:10: libsss_certmap, AlmaLinux:10: libsss_idmap, AlmaLinux:10: libsss_nss_idmap, AlmaLinux:10: libsss_nss_idmap-devel, AlmaLinux:10: libsss_sudo, AlmaLinux:10: python3-libipa_hbac, AlmaLinux:10: python3-libsss_nss_idmap, AlmaLinux:10: python3-sss and 19 more&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474)
  * sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:41937</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-363461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363461</link>
      <description>EUVD-2026-363461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-14474</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14474</link>
      <description>&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-14474</guid>
    </item>
    <item>
      <title>GHSA-2vq9-j58h-2qj3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2vq9-j58h-2qj3</link>
      <description>&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2vq9-j58h-2qj3</guid>
    </item>
    <item>
      <title>OESA-2026-3149 — sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: sssd&lt;/p&gt;
&lt;p&gt;Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD&amp;amp;apos;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.(CVE-2026-14474)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: sssd&lt;/p&gt;
&lt;p&gt;Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD&amp;amp;apos;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.(CVE-2026-14474)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3149</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21290-1 — Security update for sssd</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21290-1</link>
      <description>&lt;p&gt;Security update for sssd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sssd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21290-1</guid>
    </item>
    <item>
      <title>RHSA-2026:46482 — Red Hat Security Advisory: sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:46482</link>
      <description>&lt;p&gt;sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:46482</guid>
    </item>
    <item>
      <title>RLSA-2026:41937 — Important: sssd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:41937</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: sssd&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474)&lt;/p&gt;
&lt;p&gt;* sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: sssd&lt;/p&gt;
&lt;p&gt;The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474)&lt;/p&gt;
&lt;p&gt;* sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:41937</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22591-1 — Security update for sssd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22591-1</link>
      <description>&lt;p&gt;Security update for sssd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sssd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22591-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-14474</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14474</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: sssd, Ubuntu:Pro:18.04:LTS: sssd, Ubuntu:Pro:20.04:LTS: sssd, Ubuntu:22.04:LTS: sssd, Ubuntu:24.04:LTS: sssd, Ubuntu:25.10: sssd, Ubuntu:26.04:LTS: sssd&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: sssd, Ubuntu:Pro:18.04:LTS: sssd, Ubuntu:Pro:20.04:LTS: sssd, Ubuntu:22.04:LTS: sssd, Ubuntu:24.04:LTS: sssd, Ubuntu:25.10: sssd, Ubuntu:26.04:LTS: sssd&lt;/p&gt;
&lt;p&gt;A flaw was found in SSSD&amp;#39;s LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14474</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2419 — Red Hat Enterprise Linux (sssd, glib, c-ares): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2419</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2419</guid>
    </item>
  </channel>
</rss>
