RHSA-2026:49842: Important: sssd security update
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.Security Fix(es): sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sssdto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/python3-sssto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/python3-sss-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/python3-sss-murmurto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/python3-sss-murmur-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/python3-sssdconfigto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-adto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-ad-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-clientto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-client-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-commonto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-common-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-common-pacto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-common-pac-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-dbusto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-dbus-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-debugsourceto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-idpto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-idp-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-ipato a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-ipa-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-kcmto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-kcm-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-krb5to a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-krb5-commonto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-krb5-common-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-krb5-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-ldapto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-nfs-idmapto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-nfs-idmap-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-polkit-rulesto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-proxyto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-proxy-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-toolsto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-winbind-idmapto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
redhat/sssd-winbind-idmap-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.2-4.el8_8.4 - Upgrade
Upgrade
sssdto a version that resolves this vulnerability.Patch CVE-2026-14476 - Upgrade
Upgrade
sssdto a version that resolves this vulnerability.Patch CVE-2026-14474
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49842?
The severity of RHSA-2026:49842 is categorized as important.
What is affected by RHSA-2026:49842?
RHSA-2026:49842 affects the System Security Services Daemon (SSSD) and related debugging packages.
How do I fix RHSA-2026:49842?
To fix RHSA-2026:49842, apply the latest security update for SSSD as provided by Red Hat.
What type of vulnerability is identified in RHSA-2026:49842?
RHSA-2026:49842 identifies a path traversal vulnerability.
What is the impact of the vulnerability in RHSA-2026:49842?
The impact of the vulnerability in RHSA-2026:49842 could lead to unauthorized access to system paths and sensitive information.