It was reported to upstream that realmd is using untrusted data when configuring sssd.conf and/or smb.conf: https://bugs.freedesktop.org/show_bug.cgi?id=89207 No patches are available at the time of writing.
Commits available upstream.
Relevant commits: commit 6d5ac47cc22c273a55bea89dffbe537a3c86ad2c Author: Stef Walter <stefw> Date: Tue Apr 14 11:30:53 2015 +0200 service: Limit the characters we read from LDAP We strictly limit this to characters expected in domain names. commit 502980a8a17eddb5fe3d16bcad229a6d0ba11065 Author: Stef Walter <stefw> Date: Sat Apr 11 13:29:40 2015 +0200 service: Only accept specific characters when parsing MSCLDAP response This provides an extra layer of protection against injecting odd characters into configuration files.
Created attachment 1014276 [details] Validate text from LDAP Combined patch for this issue.
realmd-0.16.0-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
realmd-0.15.2-2.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:2184 https://rhn.redhat.com/errata/RHSA-2015-2184.html