Fedora Account System
Red Hat Associate
Red Hat Customer
The ad_gpo_extract_smb_components() function in SSSD's AD GPO provider converts backslashes to forward slashes in the gPCFileSysPath LDAP attribute but does not sanitize .. path components. A differential between libsmbclient's path clamping (resolves .. at the share root) and the kernel's path resolution (resolves .. fully) allows an attacker with AD GPO management access to write files outside the GPO cache directory as root. On SELinux-enforcing systems (the default on RHEL), the traversal can target /var/lib/sss/pubconf/krb5.include.d/ (labeled sssd_public_t), enabling Kerberos KDC redirection and authentication bypass. On SELinux-permissive or disabled systems, arbitrary file write as root is possible.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:41937 https://access.redhat.com/errata/RHSA-2026:41937
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:42122 https://access.redhat.com/errata/RHSA-2026:42122
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:46482 https://access.redhat.com/errata/RHSA-2026:46482
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46990 https://access.redhat.com/errata/RHSA-2026:46990
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:49844 https://access.redhat.com/errata/RHSA-2026:49844
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:49841 https://access.redhat.com/errata/RHSA-2026:49841
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:49842 https://access.redhat.com/errata/RHSA-2026:49842
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:49840 https://access.redhat.com/errata/RHSA-2026:49840
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:49843 https://access.redhat.com/errata/RHSA-2026:49843
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49839 https://access.redhat.com/errata/RHSA-2026:49839
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:50109 https://access.redhat.com/errata/RHSA-2026:50109