Fedora Account System
Red Hat Associate
Red Hat Customer
When ldap_sudo_search_base is not explicitly configured (the default), SSSD falls back to the domain's root DN and searches the entire LDAP directory tree for objects matching (objectClass=sudoRole) with SUBTREE scope. Any LDAP principal with write access to any subtree can create a sudoRole object granting arbitrary sudo privileges on every SSSD-enrolled host. This affects sudo_provider = ldap and sudo_provider = ad (which delegates to sdap_sudo_init()). sudo_provider = ipa is NOT affected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:41937 https://access.redhat.com/errata/RHSA-2026:41937
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:42122 https://access.redhat.com/errata/RHSA-2026:42122
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:46482 https://access.redhat.com/errata/RHSA-2026:46482
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46990 https://access.redhat.com/errata/RHSA-2026:46990
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:49844 https://access.redhat.com/errata/RHSA-2026:49844
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:49841 https://access.redhat.com/errata/RHSA-2026:49841
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:49842 https://access.redhat.com/errata/RHSA-2026:49842
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:49840 https://access.redhat.com/errata/RHSA-2026:49840
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:49843 https://access.redhat.com/errata/RHSA-2026:49843
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49839 https://access.redhat.com/errata/RHSA-2026:49839
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:50109 https://access.redhat.com/errata/RHSA-2026:50109
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:54599 https://access.redhat.com/errata/RHSA-2026:54599
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:54581 https://access.redhat.com/errata/RHSA-2026:54581
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:54553 https://access.redhat.com/errata/RHSA-2026:54553
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:54187 https://access.redhat.com/errata/RHSA-2026:54187
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:57483 https://access.redhat.com/errata/RHSA-2026:57483
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:56911 https://access.redhat.com/errata/RHSA-2026:56911
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:56786 https://access.redhat.com/errata/RHSA-2026:56786
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:56853 https://access.redhat.com/errata/RHSA-2026:56853
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:60019 https://access.redhat.com/errata/RHSA-2026:60019
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:59831 https://access.redhat.com/errata/RHSA-2026:59831
This comment was flagged as spam, view the edit history to see the original text if required.