[Git][security-tracker-team/security-tracker][master] sssd fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 23:49:14 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2417d485 by Moritz Muehlenhoff at 2026-09-05T00:48:49+02:00
sssd fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -38018,7 +38018,7 @@ CVE-2026-69100 (LAMP Rapid Development Platform through 5.6.2, fixed in commit 8
 CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization vulnerabi ...)
 	NOT-FOR-US: kotaemon
 CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...)
-	- sssd <unfixed> (bug #1143947)
+	- sssd 2.13.1-2 (bug #1143947)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509760
 CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401  ...)
@@ -38368,7 +38368,7 @@ CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and
 CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update R ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function  ...)
-	- sssd <unfixed> (bug #1143600)
+	- sssd 2.13.1-2 (bug #1143600)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509761
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
@@ -38708,7 +38708,7 @@ CVE-2026-68930 (Russh is a Rust SSH client & server library. Prior to 0.62.5, ru
 CVE-2026-68869
 	REJECTED
 CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function i ...)
-	- sssd <unfixed> (bug #1143600)
+	- sssd 2.13.1-2 (bug #1143600)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
 CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information disclosure vulner ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2417d4856ef9f141db1cbb90527a296663ad3f61

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2417d4856ef9f141db1cbb90527a296663ad3f61
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/e8a9d6b0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list