OracleLinux: Critical SSSD Security Advisory ELSA-2021-3336
Summary
[1.16.5-10.0.1] - Revert Redhat's change of disallowing duplicated incomplete gid when "id_provider=ldap" is used, which caused regression in AD environment. [Orabug: 29286774] [Doc ID 2605732.1] [1.16.5-10.10] - Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down [1.16.5-10.9] - Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
SRPMs
https://oss.oracle.com:443/ol7/SRPMS-updates/sssd-1.16.5-10.0.1.el7_9.10.src.rpm
x86_64
libipa_hbac-1.16.5-10.0.1.el7_9.10.i686.rpm libipa_hbac-1.16.5-10.0.1.el7_9.10.x86_64.rpm libipa_hbac-devel-1.16.5-10.0.1.el7_9.10.i686.rpm libipa_hbac-devel-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_autofs-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_certmap-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_certmap-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_certmap-devel-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_certmap-devel-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_idmap-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_idmap-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_idmap-devel-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_idmap-devel-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_nss_idmap-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_nss_idmap-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_nss_idmap-devel-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_nss_idmap-devel-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_simpleifp-1.16.5-10.0.1.el7_9.10.i686.rpm libsss_simpleifp-1.16.5-10.0.1.el7_9.10.x86_64.rpm libsss_simpleifp-devel-1.16.5-10.0.1.el7_9.10...
Read the Full Advisoryaarch64