[Git][security-tracker-team/security-tracker][master] sssd fixed in sid
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 4 23:51:13 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dcb47247 by Moritz Muehlenhoff at 2026-09-05T00:50:50+02:00
sssd fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -63866,7 +63866,7 @@ CVE-2026-14487 (The Simple Coherent Form plugin for WordPress is vulnerable to a
CVE-2026-14482 (The \u591a\u8bf4\u793e\u4f1a\u5316\u8bc4\u8bba\u6846 plugin for WordPr ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14476 (A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_ ...)
- - sssd <unfixed> (bug #1141769)
+ - sssd 2.13.1-1 (bug #1141769)
[trixie] - sssd <no-dsa> (Minor issue)
[bookworm] - sssd <postponed> (Minor issue)
[bullseye] - sssd <postponed> (Minor issue)
@@ -63876,7 +63876,7 @@ CVE-2026-14476 (A path traversal flaw was found in SSSD's AD GPO provider. The a
NOTE: Fixed by: https://github.com/SSSD/sssd/commit/ef5c2f9a34cba9e7e2791be13de2cb1443918976 (sssd-2-10 branch)
NOTE: Fixed by: https://github.com/SSSD/sssd/commit/91017d89f44da47ae16c140e94a5bcafc43badb5 (sssd-2-9 branch)
CVE-2026-14474 (A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...)
- - sssd <unfixed> (bug #1141769)
+ - sssd 2.13.1-1 (bug #1141769)
[trixie] - sssd <no-dsa> (Minor issue)
[bookworm] - sssd <postponed> (Minor issue)
[bullseye] - sssd <postponed> (Minor issue)
@@ -69625,7 +69625,7 @@ CVE-2026-13149 (brace-expansion through 5.0.6 is vulnerable to denial of service
[bullseye] - node-brace-expansion <postponed> (Minor issue)
NOTE: https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754
CVE-2026-12610 (A flaw was found in sssd. When authenticating with a YubiKey, the SSSD ...)
- - sssd <unfixed> (bug #1141323)
+ - sssd 2.13.1-1 (bug #1141323)
[trixie] - sssd <no-dsa> (Minor issue)
[bookworm] - sssd <postponed> (Minor issue)
[bullseye] - sssd <postponed> (Minor issue)
@@ -121227,7 +121227,7 @@ CVE-2026-6388 (A flaw was found in ArgoCD Image Updater. This vulnerability allo
CVE-2026-6383 (A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evalua ...)
NOT-FOR-US: KubeVirt
CVE-2026-6245 (A flaw was found in the System Security Services Daemon (SSSD). The pa ...)
- - sssd <unfixed> (bug #1134269)
+ - sssd 2.13.1-1 (bug #1134269)
[trixie] - sssd <no-dsa> (Minor issue)
[bookworm] - sssd <not-affected> (Vulnerable code introduced later)
[bullseye] - sssd <not-affected> (Vulnerable code introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dcb4724772388c16232dc03122e46b71aa3993b6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dcb4724772388c16232dc03122e46b71aa3993b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/a9735261/attachment.htm>
More information about the debian-security-tracker-commits
mailing list