https://bugzilla.redhat.com/show_bug.cgi?id=2402728
Bug ID: 2402728 Summary: CVE-2025-11561 sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems [fedora-all] Product: Fedora Version: 42 Status: NEW Whiteboard: {"flaws": ["1fb766e2-a79d-4ca8-97b7-362f32c866ca"]} Component: sssd Keywords: Security, SecurityTracking Severity: high Priority: high Assignee: sssd-maintainers@lists.fedoraproject.org Reporter: abhraj@redhat.com QA Contact: extras-qa@fedoraproject.org CC: abokovoy@redhat.com, atikhono@redhat.com, lslebodn@redhat.com, pbrezina@redhat.com, sbose@redhat.com, ssorce@redhat.com, sssd-maintainers@lists.fedoraproject.org Blocks: 2402727 Target Milestone: --- Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT. https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essenti...
https://bugzilla.redhat.com/show_bug.cgi?id=2402728
Alexey Tikhonov atikhono@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |POST Assignee|sssd-maintainers@lists.fedo |atikhono@redhat.com |raproject.org |
--- Comment #1 from Alexey Tikhonov atikhono@redhat.com --- Pushed PR: https://github.com/SSSD/sssd/pull/8136
* `sssd-2-11` * a08e5862693ed1191ba464351ae43c779b509096 - krb5: disable Kerberos localauth an2ln plugin for AD/IPA
https://bugzilla.redhat.com/show_bug.cgi?id=2402728
Alexey Tikhonov atikhono@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|POST |MODIFIED
--- Comment #2 from Alexey Tikhonov atikhono@redhat.com --- https://bodhi.fedoraproject.org/updates/FEDORA-2025-5f49ddd4af
sssd-maintainers@lists.fedoraproject.org