Bug 2496581 (CVE-2026-14476) - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
Summary: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSy...
Keywords:
Status: NEW
Alias: CVE-2026-14476
Deadline: 2026-07-07
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2497650
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-02 15:32 UTC by OSIDB Bzimport
Modified: 2026-09-03 12:01 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:41937 0 None None None 2026-07-20 11:11:56 UTC
Red Hat Product Errata RHSA-2026:42122 0 None None None 2026-07-20 21:43:11 UTC
Red Hat Product Errata RHSA-2026:46482 0 None None None 2026-07-27 10:11:16 UTC
Red Hat Product Errata RHSA-2026:46990 0 None None None 2026-07-28 01:01:45 UTC
Red Hat Product Errata RHSA-2026:49839 0 None None None 2026-08-04 03:14:21 UTC
Red Hat Product Errata RHSA-2026:49840 0 None None None 2026-08-04 01:58:26 UTC
Red Hat Product Errata RHSA-2026:49841 0 None None None 2026-08-04 01:04:43 UTC
Red Hat Product Errata RHSA-2026:49842 0 None None None 2026-08-04 01:52:32 UTC
Red Hat Product Errata RHSA-2026:49843 0 None None None 2026-08-04 02:07:23 UTC
Red Hat Product Errata RHSA-2026:49844 0 None None None 2026-08-04 01:04:09 UTC
Red Hat Product Errata RHSA-2026:50109 0 None None None 2026-08-04 16:01:44 UTC
Red Hat Product Errata RHSA-2026:54187 0 None None None 2026-08-20 15:17:14 UTC
Red Hat Product Errata RHSA-2026:54553 0 None None None 2026-08-19 15:19:25 UTC
Red Hat Product Errata RHSA-2026:54581 0 None None None 2026-08-18 12:07:25 UTC
Red Hat Product Errata RHSA-2026:54599 0 None None None 2026-08-18 11:57:09 UTC
Red Hat Product Errata RHSA-2026:54769 0 None None None 2026-08-18 12:25:43 UTC
Red Hat Product Errata RHSA-2026:56786 0 None None None 2026-08-31 02:02:55 UTC
Red Hat Product Errata RHSA-2026:56853 0 None None None 2026-08-31 02:04:28 UTC
Red Hat Product Errata RHSA-2026:56911 0 None None None 2026-08-31 02:02:38 UTC
Red Hat Product Errata RHSA-2026:57483 0 None None None 2026-08-26 15:55:28 UTC
Red Hat Product Errata RHSA-2026:59831 0 None None None 2026-09-03 12:01:19 UTC
Red Hat Product Errata RHSA-2026:60019 0 None None None 2026-09-03 08:59:10 UTC

Description OSIDB Bzimport 2026-07-02 15:32:22 UTC
The ad_gpo_extract_smb_components() function in SSSD's AD GPO provider converts backslashes to forward slashes in the gPCFileSysPath LDAP attribute but does not sanitize .. path components. A differential between libsmbclient's path clamping (resolves .. at the share root) and the kernel's path resolution (resolves .. fully) allows an attacker with AD GPO management access to write files outside the GPO cache directory as root.

On SELinux-enforcing systems (the default on RHEL), the traversal can target /var/lib/sss/pubconf/krb5.include.d/ (labeled sssd_public_t), enabling Kerberos KDC redirection and authentication bypass. On SELinux-permissive or disabled systems, arbitrary file write as root is possible.

Comment 1 errata-xmlrpc 2026-07-20 11:11:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:41937 https://access.redhat.com/errata/RHSA-2026:41937

Comment 2 errata-xmlrpc 2026-07-20 21:43:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:42122 https://access.redhat.com/errata/RHSA-2026:42122

Comment 3 errata-xmlrpc 2026-07-27 10:11:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:46482 https://access.redhat.com/errata/RHSA-2026:46482

Comment 4 errata-xmlrpc 2026-07-28 01:01:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:46990 https://access.redhat.com/errata/RHSA-2026:46990

Comment 5 errata-xmlrpc 2026-08-04 01:04:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:49844 https://access.redhat.com/errata/RHSA-2026:49844

Comment 6 errata-xmlrpc 2026-08-04 01:04:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:49841 https://access.redhat.com/errata/RHSA-2026:49841

Comment 7 errata-xmlrpc 2026-08-04 01:52:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:49842 https://access.redhat.com/errata/RHSA-2026:49842

Comment 8 errata-xmlrpc 2026-08-04 01:58:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:49840 https://access.redhat.com/errata/RHSA-2026:49840

Comment 9 errata-xmlrpc 2026-08-04 02:07:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:49843 https://access.redhat.com/errata/RHSA-2026:49843

Comment 10 errata-xmlrpc 2026-08-04 03:14:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49839 https://access.redhat.com/errata/RHSA-2026:49839

Comment 11 errata-xmlrpc 2026-08-04 16:01:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:50109 https://access.redhat.com/errata/RHSA-2026:50109

Comment 12 errata-xmlrpc 2026-08-18 11:57:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:54599 https://access.redhat.com/errata/RHSA-2026:54599

Comment 13 errata-xmlrpc 2026-08-18 12:07:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:54581 https://access.redhat.com/errata/RHSA-2026:54581

Comment 14 errata-xmlrpc 2026-08-18 12:25:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769

Comment 15 errata-xmlrpc 2026-08-19 15:19:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:54553 https://access.redhat.com/errata/RHSA-2026:54553

Comment 16 errata-xmlrpc 2026-08-20 15:17:13 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2026:54187 https://access.redhat.com/errata/RHSA-2026:54187

Comment 17 errata-xmlrpc 2026-08-26 15:55:26 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:57483 https://access.redhat.com/errata/RHSA-2026:57483

Comment 18 errata-xmlrpc 2026-08-31 02:02:37 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2026:56911 https://access.redhat.com/errata/RHSA-2026:56911

Comment 19 errata-xmlrpc 2026-08-31 02:02:54 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2026:56786 https://access.redhat.com/errata/RHSA-2026:56786

Comment 20 errata-xmlrpc 2026-08-31 02:04:26 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2026:56853 https://access.redhat.com/errata/RHSA-2026:56853

Comment 21 errata-xmlrpc 2026-09-03 08:59:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2026:60019 https://access.redhat.com/errata/RHSA-2026:60019

Comment 22 errata-xmlrpc 2026-09-03 12:01:16 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2026:59831 https://access.redhat.com/errata/RHSA-2026:59831


Note You need to log in before you can comment on or make changes to this bug.