openSUSE-SU-2026:21748-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21748-1
openSUSE-SU-2026:21748-1
Summary: Security update for sssd
Details: This update for sssd fixes the following issues: Security issues fixed: - CVE-2026-68742: insufficient validation in the NSS responder can lead to an out-of-bounds read and a process crash when a crafted GETHOSTBYADDR request is sent to the NSS responder socket (bsc#1273922). - CVE-2026-68743: insufficient validation in the PAM responder can lead to an out-of-bounds read and a process crash when a crafted protocol v1 request is processed (bsc#1273925). - CVE-2026-68744: improper memory management in the NSS responder can lead to uninitialized heap memory disclosure from the `sssd_nss` process (bsc#1273924). Other updates and bugfixes: - Add `systemd-tmpfiles` configuration file to populate `/var/lib/sss` with the correct permissions on transactional servers (bsc#1274748).
References: , https://bugzilla.suse.com/1273009, https://bugzilla.suse.com/1273922, https://bugzilla.suse.com/1273924, https://bugzilla.suse.com/1273925, https://bugzilla.suse.com/1274748, https://www.suse.com/security/cve/CVE-2026-68742, https://www.suse.com/security/cve/CVE-2026-68743, https://www.suse.com/security/cve/CVE-2026-68744
Affected packages
Package
Name: sssd
Purl: pkg:rpm/opensuse/sssd&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
