Home / mailingsPDF  

[USN-8672-1] SSSD vulnerability

Posted on 02 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-USN-8672-1
August 25, 2026

sssd vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

SSSD could be made to crash if it interacted with a smartcard or Yubikey

Software Description:
- sssd: System Security Services Daemon

Details:

It was discovered that the SSSD PAM responder may crash if a physically
proximate attacker manipulates a smartcard or Yubikey. Non-malicious
physically proximate users may not be able to log in depending upon the
details of their legitimate smartcard or Yubikey.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libpam-sss 2.12.0-1ubuntu5.3
sssd-common 2.12.0-1ubuntu5.3

Ubuntu 24.04 LTS
libpam-sss 2.9.4-1.1ubuntu6.7
sssd-common 2.9.4-1.1ubuntu6.7

Ubuntu 22.04 LTS
libpam-sss 2.6.3-1ubuntu3.8
sssd-common 2.6.3-1ubuntu3.8

After a standard system update you need to restart sssd to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-USN-8672-1
CVE-2026-12610

Package Information:
https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3
https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7
https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8

--===============1585147662761083581==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP