Bug 2496581 (CVE-2026-14476) - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
Summary: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSy...
Keywords:
Status: NEW
Alias: CVE-2026-14476
Deadline: 2026-07-07
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2497650
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-02 15:32 UTC by OSIDB Bzimport
Modified: 2026-08-04 16:01 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:41937 0 None None None 2026-07-20 11:11:56 UTC
Red Hat Product Errata RHSA-2026:42122 0 None None None 2026-07-20 21:43:11 UTC
Red Hat Product Errata RHSA-2026:46482 0 None None None 2026-07-27 10:11:16 UTC
Red Hat Product Errata RHSA-2026:46990 0 None None None 2026-07-28 01:01:45 UTC
Red Hat Product Errata RHSA-2026:49839 0 None None None 2026-08-04 03:14:21 UTC
Red Hat Product Errata RHSA-2026:49840 0 None None None 2026-08-04 01:58:26 UTC
Red Hat Product Errata RHSA-2026:49841 0 None None None 2026-08-04 01:04:43 UTC
Red Hat Product Errata RHSA-2026:49842 0 None None None 2026-08-04 01:52:32 UTC
Red Hat Product Errata RHSA-2026:49843 0 None None None 2026-08-04 02:07:23 UTC
Red Hat Product Errata RHSA-2026:49844 0 None None None 2026-08-04 01:04:09 UTC
Red Hat Product Errata RHSA-2026:50109 0 None None None 2026-08-04 16:01:44 UTC

Description OSIDB Bzimport 2026-07-02 15:32:22 UTC
The ad_gpo_extract_smb_components() function in SSSD's AD GPO provider converts backslashes to forward slashes in the gPCFileSysPath LDAP attribute but does not sanitize .. path components. A differential between libsmbclient's path clamping (resolves .. at the share root) and the kernel's path resolution (resolves .. fully) allows an attacker with AD GPO management access to write files outside the GPO cache directory as root.

On SELinux-enforcing systems (the default on RHEL), the traversal can target /var/lib/sss/pubconf/krb5.include.d/ (labeled sssd_public_t), enabling Kerberos KDC redirection and authentication bypass. On SELinux-permissive or disabled systems, arbitrary file write as root is possible.

Comment 1 errata-xmlrpc 2026-07-20 11:11:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:41937 https://access.redhat.com/errata/RHSA-2026:41937

Comment 2 errata-xmlrpc 2026-07-20 21:43:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:42122 https://access.redhat.com/errata/RHSA-2026:42122

Comment 3 errata-xmlrpc 2026-07-27 10:11:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:46482 https://access.redhat.com/errata/RHSA-2026:46482

Comment 4 errata-xmlrpc 2026-07-28 01:01:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:46990 https://access.redhat.com/errata/RHSA-2026:46990

Comment 5 errata-xmlrpc 2026-08-04 01:04:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:49844 https://access.redhat.com/errata/RHSA-2026:49844

Comment 6 errata-xmlrpc 2026-08-04 01:04:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:49841 https://access.redhat.com/errata/RHSA-2026:49841

Comment 7 errata-xmlrpc 2026-08-04 01:52:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:49842 https://access.redhat.com/errata/RHSA-2026:49842

Comment 8 errata-xmlrpc 2026-08-04 01:58:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:49840 https://access.redhat.com/errata/RHSA-2026:49840

Comment 9 errata-xmlrpc 2026-08-04 02:07:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:49843 https://access.redhat.com/errata/RHSA-2026:49843

Comment 10 errata-xmlrpc 2026-08-04 03:14:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49839 https://access.redhat.com/errata/RHSA-2026:49839

Comment 11 errata-xmlrpc 2026-08-04 16:01:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:50109 https://access.redhat.com/errata/RHSA-2026:50109


Note You need to log in before you can comment on or make changes to this bug.