SUSE update for sssd



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-3758
CWE-ID CWE-362
Exploitation vector Network
Public exploit N/A
Vulnerable software
SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

Basesystem Module
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

sssd-common-64bit
Operating systems & Components / Operating system package or component

sssd-common-64bit-debuginfo
Operating systems & Components / Operating system package or component

python3-sss-murmur-debuginfo
Operating systems & Components / Operating system package or component

python3-sss-murmur
Operating systems & Components / Operating system package or component

python3-sss_nss_idmap-debuginfo
Operating systems & Components / Operating system package or component

libnfsidmap-sss-debuginfo
Operating systems & Components / Operating system package or component

python3-ipa_hbac
Operating systems & Components / Operating system package or component

libnfsidmap-sss
Operating systems & Components / Operating system package or component

python3-ipa_hbac-debuginfo
Operating systems & Components / Operating system package or component

python3-sss_nss_idmap
Operating systems & Components / Operating system package or component

sssd-common-32bit-debuginfo
Operating systems & Components / Operating system package or component

sssd-common-32bit
Operating systems & Components / Operating system package or component

libipa_hbac0-debuginfo
Operating systems & Components / Operating system package or component

libipa_hbac0
Operating systems & Components / Operating system package or component

libsss_simpleifp0
Operating systems & Components / Operating system package or component

sssd-kcm-debuginfo
Operating systems & Components / Operating system package or component

sssd-proxy
Operating systems & Components / Operating system package or component

sssd-dbus
Operating systems & Components / Operating system package or component

libsss_simpleifp0-debuginfo
Operating systems & Components / Operating system package or component

sssd-kcm
Operating systems & Components / Operating system package or component

python3-sssd-config-debuginfo
Operating systems & Components / Operating system package or component

sssd-tools-debuginfo
Operating systems & Components / Operating system package or component

libsss_nss_idmap-devel
Operating systems & Components / Operating system package or component

sssd-ipa-debuginfo
Operating systems & Components / Operating system package or component

sssd-winbind-idmap
Operating systems & Components / Operating system package or component

sssd-tools
Operating systems & Components / Operating system package or component

sssd-krb5-debuginfo
Operating systems & Components / Operating system package or component

sssd-krb5
Operating systems & Components / Operating system package or component

sssd-ad-debuginfo
Operating systems & Components / Operating system package or component

libsss_certmap-devel
Operating systems & Components / Operating system package or component

python3-sssd-config
Operating systems & Components / Operating system package or component

sssd-ad
Operating systems & Components / Operating system package or component

sssd-ipa
Operating systems & Components / Operating system package or component

libsss_simpleifp-devel
Operating systems & Components / Operating system package or component

libipa_hbac-devel
Operating systems & Components / Operating system package or component

sssd-dbus-debuginfo
Operating systems & Components / Operating system package or component

libsss_idmap-devel
Operating systems & Components / Operating system package or component

sssd-winbind-idmap-debuginfo
Operating systems & Components / Operating system package or component

sssd-proxy-debuginfo
Operating systems & Components / Operating system package or component

libsss_nss_idmap0
Operating systems & Components / Operating system package or component

libsss_certmap0
Operating systems & Components / Operating system package or component

libsss_idmap0
Operating systems & Components / Operating system package or component

sssd-krb5-common
Operating systems & Components / Operating system package or component

sssd-ldap-debuginfo
Operating systems & Components / Operating system package or component

sssd-common-debuginfo
Operating systems & Components / Operating system package or component

sssd
Operating systems & Components / Operating system package or component

libsss_nss_idmap0-debuginfo
Operating systems & Components / Operating system package or component

sssd-debugsource
Operating systems & Components / Operating system package or component

sssd-ldap
Operating systems & Components / Operating system package or component

sssd-krb5-common-debuginfo
Operating systems & Components / Operating system package or component

libsss_certmap0-debuginfo
Operating systems & Components / Operating system package or component

sssd-common
Operating systems & Components / Operating system package or component

libsss_idmap0-debuginfo
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Race condition

EUVDB-ID: #VU88857

Risk: Medium

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-3758

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a race condition where the GPO policy is not consistently applied for authenticated users. A remote user can exploit the race and gain unauthorized access to the system.

Mitigation

Update the affected package sssd to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro: 5.5

Basesystem Module: 15-SP5

SUSE Linux Enterprise Server for SAP Applications 15: SP5

SUSE Linux Enterprise Server 15: SP5

SUSE Linux Enterprise Real Time 15: SP5

SUSE Linux Enterprise High Performance Computing 15: SP5

SUSE Linux Enterprise Desktop 15: SP5

openSUSE Leap: 15.5

sssd-common-64bit: before 2.5.2-150500.10.17.1

sssd-common-64bit-debuginfo: before 2.5.2-150500.10.17.1

python3-sss-murmur-debuginfo: before 2.5.2-150500.10.17.1

python3-sss-murmur: before 2.5.2-150500.10.17.1

python3-sss_nss_idmap-debuginfo: before 2.5.2-150500.10.17.1

libnfsidmap-sss-debuginfo: before 2.5.2-150500.10.17.1

python3-ipa_hbac: before 2.5.2-150500.10.17.1

libnfsidmap-sss: before 2.5.2-150500.10.17.1

python3-ipa_hbac-debuginfo: before 2.5.2-150500.10.17.1

python3-sss_nss_idmap: before 2.5.2-150500.10.17.1

sssd-common-32bit-debuginfo: before 2.5.2-150500.10.17.1

sssd-common-32bit: before 2.5.2-150500.10.17.1

libipa_hbac0-debuginfo: before 2.5.2-150500.10.17.1

libipa_hbac0: before 2.5.2-150500.10.17.1

libsss_simpleifp0: before 2.5.2-150500.10.17.1

sssd-kcm-debuginfo: before 2.5.2-150500.10.17.1

sssd-proxy: before 2.5.2-150500.10.17.1

sssd-dbus: before 2.5.2-150500.10.17.1

libsss_simpleifp0-debuginfo: before 2.5.2-150500.10.17.1

sssd-kcm: before 2.5.2-150500.10.17.1

python3-sssd-config-debuginfo: before 2.5.2-150500.10.17.1

sssd-tools-debuginfo: before 2.5.2-150500.10.17.1

libsss_nss_idmap-devel: before 2.5.2-150500.10.17.1

sssd-ipa-debuginfo: before 2.5.2-150500.10.17.1

sssd-winbind-idmap: before 2.5.2-150500.10.17.1

sssd-tools: before 2.5.2-150500.10.17.1

sssd-krb5-debuginfo: before 2.5.2-150500.10.17.1

sssd-krb5: before 2.5.2-150500.10.17.1

sssd-ad-debuginfo: before 2.5.2-150500.10.17.1

libsss_certmap-devel: before 2.5.2-150500.10.17.1

python3-sssd-config: before 2.5.2-150500.10.17.1

sssd-ad: before 2.5.2-150500.10.17.1

sssd-ipa: before 2.5.2-150500.10.17.1

libsss_simpleifp-devel: before 2.5.2-150500.10.17.1

libipa_hbac-devel: before 2.5.2-150500.10.17.1

sssd-dbus-debuginfo: before 2.5.2-150500.10.17.1

libsss_idmap-devel: before 2.5.2-150500.10.17.1

sssd-winbind-idmap-debuginfo: before 2.5.2-150500.10.17.1

sssd-proxy-debuginfo: before 2.5.2-150500.10.17.1

libsss_nss_idmap0: before 2.5.2-150500.10.17.1

libsss_certmap0: before 2.5.2-150500.10.17.1

libsss_idmap0: before 2.5.2-150500.10.17.1

sssd-krb5-common: before 2.5.2-150500.10.17.1

sssd-ldap-debuginfo: before 2.5.2-150500.10.17.1

sssd-common-debuginfo: before 2.5.2-150500.10.17.1

sssd: before 2.5.2-150500.10.17.1

libsss_nss_idmap0-debuginfo: before 2.5.2-150500.10.17.1

sssd-debugsource: before 2.5.2-150500.10.17.1

sssd-ldap: before 2.5.2-150500.10.17.1

sssd-krb5-common-debuginfo: before 2.5.2-150500.10.17.1

libsss_certmap0-debuginfo: before 2.5.2-150500.10.17.1

sssd-common: before 2.5.2-150500.10.17.1

libsss_idmap0-debuginfo: before 2.5.2-150500.10.17.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2024/suse-su-20241579-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###