Debian Package Tracker
Register | Log in
Subscribe

sssd

System Security Services Daemon -- metapackage

Choose email to subscribe with

general
  • source: sssd (main)
  • version: 2.13.1-2
  • maintainer: Debian SSSD Team (DMD)
  • uploaders: Dominik George [DMD] – Timo Aaltonen [DMD]
  • arch: any
  • std-ver: 4.4.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.4.1-2
  • o-o-sec: 2.4.1-2+deb11u1
  • oldstable: 2.8.2-4+deb12u1
  • stable: 2.10.1-2
  • unstable: 2.13.1-2
versioned links
  • 2.4.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.1-2+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.8.2-4+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.10.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.0-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.13.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libipa-hbac-dev
  • libipa-hbac0t64
  • libnss-sss (2 bugs: 0, 2, 0, 0)
  • libpam-sss (5 bugs: 0, 4, 1, 0)
  • libsss-certmap-dev
  • libsss-certmap0
  • libsss-idmap-dev
  • libsss-idmap0
  • libsss-nss-idmap-dev
  • libsss-nss-idmap0
  • libsss-sudo (2 bugs: 1, 1, 0, 0)
  • python3-libipa-hbac
  • python3-libsss-nss-idmap
  • python3-sss
  • sssd (34 bugs: 0, 33, 1, 0)
  • sssd-ad (2 bugs: 0, 2, 0, 0)
  • sssd-ad-common
  • sssd-common (6 bugs: 0, 5, 1, 0)
  • sssd-dbus
  • sssd-idp (1 bugs: 0, 1, 0, 0)
  • sssd-ipa
  • sssd-kcm
  • sssd-krb5 (2 bugs: 0, 2, 0, 0)
  • sssd-krb5-common
  • sssd-ldap (2 bugs: 0, 2, 0, 0)
  • sssd-passkey
  • sssd-proxy
  • sssd-tools
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:03:53
    Last run: 2026-09-05T07:41:03.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:00:19
    Last run: 2026-02-02T15:43:14.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:02:02
    Last run: 2026-07-16T13:44:27.000Z
    Previous status: unknown

Created: 2025-11-11 Last update: 2026-09-08 18:30
7 security issues in bookworm high

There are 7 open security issues in bookworm.

3 important issues:
  • CVE-2026-68742: A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
  • CVE-2026-68743: A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
  • CVE-2026-68744: A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
4 issues postponed or untriaged:
  • CVE-2025-11561: (needs triaging) A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.
  • CVE-2026-12610: (postponed; to be fixed through a stable update) A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
  • CVE-2026-14474: (postponed; to be fixed through a stable update) A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
  • CVE-2026-14476: (postponed; to be fixed through a stable update) A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.
Created: 2026-08-03 Last update: 2026-09-08 18:30
lintian reports 6 errors and 27 warnings high
Lintian reports 6 errors and 27 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-05 Last update: 2026-09-05 10:32
7 security issues in bullseye high

There are 7 open security issues in bullseye.

3 important issues:
  • CVE-2026-68742: A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
  • CVE-2026-68743: A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
  • CVE-2026-68744: A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
4 issues postponed or untriaged:
  • CVE-2025-11561: (postponed; to be fixed through a stable update) A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.
  • CVE-2026-12610: (postponed; to be fixed through a stable update) A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
  • CVE-2026-14474: (postponed; to be fixed through a stable update) A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
  • CVE-2026-14476: (postponed; to be fixed through a stable update) A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.
Created: 2026-08-03 Last update: 2026-08-10 18:47
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-6245: A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read when processed by functions like snprintf(). A local attacker could potentially trigger this vulnerability by initiating a crafted passkey authentication request, causing the SSSD PAM responder to crash, resulting in a local Denial of Service (DoS).
Created: 2026-04-16 Last update: 2026-05-06 17:02
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-08 19:01
Depends on packages which need a new maintainer normal
The packages that sssd depends on which need a new maintainer are:
  • systemtap (#1114760)
    • Build-Depends: systemtap-sdt-dev
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2019-11-22 Last update: 2026-09-08 18:02
debian/patches: 11 patches to forward upstream low

Among the 11 debian patches available in version 2.13.1-2 of the package, we noticed the following issues:

  • 11 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-05 10:19
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.4.0).
Created: 2019-09-29 Last update: 2026-09-05 06:04
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migrates after: pcre2
    • Migration status for sssd (- to 2.13.1-3): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating sssd would introduce bugs in testing: #1129522
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Missing build on s390x
    • ∙ ∙ Piuparts check waiting for test results - https://piuparts.debian.org/sid/source/s/sssd.html
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for gdm3/50.2-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered (will not be considered a regression) ♻ (reference ♻), ppc64el: Test triggered (will not be considered a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for sssd: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered
    • ∙ ∙ Autopkgtest for sudo/1.9.17p2-7: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Test triggered
    • ∙ ∙ Lintian check waiting for test results - info
    • ∙ ∙ Reproducibility check waiting for results on arm64 - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • ∙ ∙ Depends: sssd pcre2
    • Additional info (not blocking):
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-08] Accepted sssd 2.13.1-3 (source) into unstable (Mike Gabriel)
  • [2026-09-04] Accepted sssd 2.13.1-2 (source) into unstable (Mike Gabriel)
  • [2026-09-04] Accepted sssd 2.13.1-1 (source) into unstable (Mike Gabriel)
  • [2026-05-11] sssd REMOVED from testing (Debian testing watch)
  • [2026-03-19] sssd 2.12.0-4 MIGRATED to testing (Debian testing watch)
  • [2026-03-15] Accepted sssd 2.12.0-4 (source) into unstable (Simon Josefsson)
  • [2026-03-07] Accepted sssd 2.12.0-3~exp0 (source) into experimental (Simon Josefsson)
  • [2026-02-20] sssd 2.12.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-13] Accepted sssd 2.12.0-2 (source) into unstable (Timo Aaltonen)
  • [2026-02-11] sssd 2.12.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted sssd 2.12.0-1 (source) into unstable (Timo Aaltonen)
  • [2026-02-08] sssd 2.11.1-2.1 MIGRATED to testing (Debian testing watch)
  • [2026-02-06] Accepted sssd 2.11.1-2.1 (source) into unstable (Daniel Baumann)
  • [2026-01-25] sssd REMOVED from testing (Debian testing watch)
  • [2026-01-09] Accepted sssd 2.11.1-2 (source) into unstable (Michael Tokarev)
  • [2025-11-10] Accepted sssd 2.11.1-1 (source) into unstable (Timo Aaltonen)
  • [2025-02-19] Accepted sssd 2.8.2-4+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2025-02-09] Accepted sssd 2.4.1-2+deb11u1 (source) into oldstable-security (Guilhem Moulin)
  • [2025-01-27] sssd 2.10.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-14] Accepted sssd 2.10.1-2 (source) into unstable (Timo Aaltonen)
  • [2025-01-08] Accepted sssd 2.10.1-1 (source) into unstable (Timo Aaltonen)
  • [2024-12-29] sssd 2.9.5-5 MIGRATED to testing (Debian testing watch)
  • [2024-12-20] Accepted sssd 2.9.5-5 (source) into unstable (Simon Josefsson)
  • [2024-11-26] Accepted sssd 2.9.5-4 (source) into unstable (Simon Josefsson)
  • [2024-10-22] sssd REMOVED from testing (Debian testing watch)
  • [2024-07-30] sssd 2.9.5-3 MIGRATED to testing (Debian testing watch)
  • [2024-06-04] Accepted sssd 2.9.5-3 (source) into unstable (Timo Aaltonen)
  • [2024-06-04] Accepted sssd 2.9.5-2 (source) into unstable (Timo Aaltonen)
  • [2024-05-20] Accepted sssd 2.9.5-1 (source) into unstable (Timo Aaltonen)
  • [2024-04-25] sssd REMOVED from testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 63 64
  • RC: 1
  • I&N: 57
  • M&W: 5 6
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (6, 27)
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (36, 51)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.12.0-4ubuntu1
  • 31 bugs (1 patch)
  • patches for 2.12.0-4ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing