Fedora Account System
Red Hat Associate
Red Hat Customer
The ad_gpo_extract_smb_components() function in SSSD's AD GPO provider converts backslashes to forward slashes in the gPCFileSysPath LDAP attribute but does not sanitize .. path components. A differential between libsmbclient's path clamping (resolves .. at the share root) and the kernel's path resolution (resolves .. fully) allows an attacker with AD GPO management access to write files outside the GPO cache directory as root. On SELinux-enforcing systems (the default on RHEL), the traversal can target /var/lib/sss/pubconf/krb5.include.d/ (labeled sssd_public_t), enabling Kerberos KDC redirection and authentication bypass. On SELinux-permissive or disabled systems, arbitrary file write as root is possible.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:41937 https://access.redhat.com/errata/RHSA-2026:41937
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:42122 https://access.redhat.com/errata/RHSA-2026:42122
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:46482 https://access.redhat.com/errata/RHSA-2026:46482
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46990 https://access.redhat.com/errata/RHSA-2026:46990
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:49844 https://access.redhat.com/errata/RHSA-2026:49844
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:49841 https://access.redhat.com/errata/RHSA-2026:49841
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:49842 https://access.redhat.com/errata/RHSA-2026:49842
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:49840 https://access.redhat.com/errata/RHSA-2026:49840
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:49843 https://access.redhat.com/errata/RHSA-2026:49843
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49839 https://access.redhat.com/errata/RHSA-2026:49839
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:50109 https://access.redhat.com/errata/RHSA-2026:50109
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:54599 https://access.redhat.com/errata/RHSA-2026:54599
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:54581 https://access.redhat.com/errata/RHSA-2026:54581
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:54553 https://access.redhat.com/errata/RHSA-2026:54553
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:54187 https://access.redhat.com/errata/RHSA-2026:54187
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:57483 https://access.redhat.com/errata/RHSA-2026:57483
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:56911 https://access.redhat.com/errata/RHSA-2026:56911
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:56786 https://access.redhat.com/errata/RHSA-2026:56786
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:56853 https://access.redhat.com/errata/RHSA-2026:56853
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:60019 https://access.redhat.com/errata/RHSA-2026:60019
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:59831 https://access.redhat.com/errata/RHSA-2026:59831