{"id":"SUSE-SU-2022:2763-1","summary":"Security update for sssd","details":"This update for sssd fixes the following issues:\n\n- CVE-2021-3621: Fixed shell command injection in sssctl via the logs-fetch and cache-expire subcommand (bsc#1189492).\n\n- Add 'ldap_ignore_unreadable_references' parameter to skip\n  unreadable objects referenced by 'member' attributte (bsc#1190775)\n\n- Fix 32-bit libraries package. Libraries were moved from sssd to sssd-common but \n  baselibs.conf was not updated accordingly (bsc#1182058, bsc#1196166)\n\n- Remove caches only when performing a package downgrade. The sssd daemon takes care of \n  upgrading the database format when necessary (bsc#1195552)\n","modified":"2026-03-11T07:20:53.915847Z","published":"2022-08-10T12:30:21Z","related":["CVE-2021-3621"],"upstream":["CVE-2021-3621"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20222763-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190775"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195552"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3621"}],"affected":[{"package":{"name":"sssd","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/sssd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-150400.4.5.14"}]}],"ecosystem_specific":{"binaries":[{"sssd-tools":"2.5.2-150400.4.5.14","libsss_nss_idmap0":"2.5.2-150400.4.5.14","libsss_simpleifp0":"2.5.2-150400.4.5.14","sssd-common":"2.5.2-150400.4.5.14","sssd-kcm":"2.5.2-150400.4.5.14","sssd-proxy":"2.5.2-150400.4.5.14","sssd-winbind-idmap":"2.5.2-150400.4.5.14","sssd":"2.5.2-150400.4.5.14","libsss_idmap-devel":"2.5.2-150400.4.5.14","libsss_idmap0":"2.5.2-150400.4.5.14","libsss_simpleifp-devel":"2.5.2-150400.4.5.14","python3-sssd-config":"2.5.2-150400.4.5.14","sssd-krb5-common":"2.5.2-150400.4.5.14","libipa_hbac-devel":"2.5.2-150400.4.5.14","libipa_hbac0":"2.5.2-150400.4.5.14","libsss_certmap0":"2.5.2-150400.4.5.14","sssd-dbus":"2.5.2-150400.4.5.14","sssd-krb5":"2.5.2-150400.4.5.14","sssd-ldap":"2.5.2-150400.4.5.14","libsss_certmap-devel":"2.5.2-150400.4.5.14","libsss_nss_idmap-devel":"2.5.2-150400.4.5.14","sssd-ad":"2.5.2-150400.4.5.14","sssd-ipa":"2.5.2-150400.4.5.14"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2763-1.json"}},{"package":{"name":"sssd","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/sssd&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-150400.4.5.14"}]}],"ecosystem_specific":{"binaries":[{"libsss_idmap-devel":"2.5.2-150400.4.5.14","libsss_nss_idmap-devel":"2.5.2-150400.4.5.14","sssd-ad":"2.5.2-150400.4.5.14","sssd-common":"2.5.2-150400.4.5.14","sssd-ldap":"2.5.2-150400.4.5.14","sssd-tools":"2.5.2-150400.4.5.14","libsss_simpleifp0":"2.5.2-150400.4.5.14","python3-sss-murmur":"2.5.2-150400.4.5.14","python3-sssd-config":"2.5.2-150400.4.5.14","sssd-dbus":"2.5.2-150400.4.5.14","python3-ipa_hbac":"2.5.2-150400.4.5.14","libipa_hbac0":"2.5.2-150400.4.5.14","libnfsidmap-sss":"2.5.2-150400.4.5.14","libsss_certmap-devel":"2.5.2-150400.4.5.14","libsss_idmap0":"2.5.2-150400.4.5.14","libsss_nss_idmap0":"2.5.2-150400.4.5.14","sssd-kcm":"2.5.2-150400.4.5.14","sssd-krb5-common":"2.5.2-150400.4.5.14","libsss_certmap0":"2.5.2-150400.4.5.14","libsss_simpleifp-devel":"2.5.2-150400.4.5.14","sssd-ipa":"2.5.2-150400.4.5.14","sssd-krb5":"2.5.2-150400.4.5.14","sssd-proxy":"2.5.2-150400.4.5.14","sssd-winbind-idmap":"2.5.2-150400.4.5.14","sssd":"2.5.2-150400.4.5.14","python3-sss_nss_idmap":"2.5.2-150400.4.5.14","libipa_hbac-devel":"2.5.2-150400.4.5.14"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2763-1.json"}}],"schema_version":"1.7.5"}