Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published Apr 18, 2024
7.1
HIGHCVSS 3.1
EPSS 1.03%
Description
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Affected products
No data.
Configuration 1
- < 2.9.5
Configuration 2
- 8.0
- 8.6
- 8.8
- 9.0
- 9.2
- 9.4
- 9.6
- 8.0_aarch64
- 8.6_aarch64
- 8.8_aarch64
- 9.0_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 9.6_aarch64
- 8.0_s390x
- 8.6_s390x
- 8.8_s390x
- 9.0_s390x
- 9.2_s390x
- 9.4_s390x
- 9.6_s390x
- 8.0_ppc64le
- 8.6_ppc64le
- 8.8_ppc64le
- 9.0_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 4.0
- 8.0
- 8.6
- 8.8
- 9.0
- 9.2
- 9.4
- 9.6
- 8.0_aarch64
- 8.6_aarch64
- 8.8_aarch64
- 9.0_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 9.6_aarch64
- 8.0_s390x
- 8.6_s390x
- 8.8_s390x
- 9.0_s390x
- 9.2_s390x
- 9.4_s390x
- 9.6_s390x
- 8.0_ppc64le
- 8.6_ppc64le
- 8.8_ppc64le
- 9.0_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 8.6
- 9.2
- 9.4
- 9.6
- 8.6_ppc64le
- 8.8_ppc64le
- 9.0_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 8.6
- 8.8
- 8.6
- 8.8
- 9.0
- 9.2
- 9.4
- 9.6
Configuration 3
- 38
- 39
- 40
No data.
Red Hat Enterprise Linux 8
sssd-0:2.9.4-3.el8_10
Fixed · RHSA-2024:3270
Red Hat Enterprise Linux 8
sssd-0:2.9.4-3.el8_10
Fixed · RHSA-2024:3270
Red Hat Enterprise Linux 8.6 Extended Update Support
sssd-0:2.6.2-4.el8_6.3
Fixed · RHSA-2024:1921
Red Hat Enterprise Linux 8.8 Extended Update Support
sssd-0:2.8.2-4.el8_8.2
Fixed · RHSA-2024:1922
Red Hat Enterprise Linux 9
sssd-0:2.9.4-6.el9_4
Fixed · RHSA-2024:2571
Red Hat Enterprise Linux 9
sssd-0:2.9.4-6.el9_4
Fixed · RHSA-2024:2571
Red Hat Enterprise Linux 9.0 Extended Update Support
sssd-0:2.6.2-4.el9_0.3
Fixed · RHSA-2024:1919
Red Hat Enterprise Linux 9.2 Extended Update Support
sssd-0:2.8.2-5.el9_2.4
Fixed · RHSA-2024:1920
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
sssd-0:2.6.2-4.el8_6.3
Fixed · RHSA-2024:1921
Red Hat Enterprise Linux 6
sssd
Out of support scope
Red Hat Enterprise Linux 7
sssd
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | sssd-0:2.9.4-3.el8_10 | Fixed | RHSA-2024:3270 |
| Red Hat Enterprise Linux 8 | sssd-0:2.9.4-3.el8_10 | Fixed | RHSA-2024:3270 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | sssd-0:2.6.2-4.el8_6.3 | Fixed | RHSA-2024:1921 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | sssd-0:2.8.2-4.el8_8.2 | Fixed | RHSA-2024:1922 |
| Red Hat Enterprise Linux 9 | sssd-0:2.9.4-6.el9_4 | Fixed | RHSA-2024:2571 |
| Red Hat Enterprise Linux 9 | sssd-0:2.9.4-6.el9_4 | Fixed | RHSA-2024:2571 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | sssd-0:2.6.2-4.el9_0.3 | Fixed | RHSA-2024:1919 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | sssd-0:2.8.2-5.el9_2.4 | Fixed | RHSA-2024:1920 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | sssd-0:2.6.2-4.el8_6.3 | Fixed | RHSA-2024:1921 |
| Red Hat Enterprise Linux 6 | sssd | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | sssd | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
A mitigation can be applied to the sssd.conf file that would make the occurrence of the race condition more difficult:
1. Increase the GPO cache time out editing the following configuration directive in sssd.conf file: a) ad_gpo_cache_timeout = 3600 Ps.: This value (3600) should make the cache time out in one hour but would make GPO updates propagation from AD server to local machines take longer.
[1] https://access.redhat.com/documentation/pt-br/red_hat_enterprise_linux/7/html/windows_integration_guide/sssd-gpo
Red Hat statement
This flaw is triggered by a race condition which makes it difficult to exploit. Also, it depends on non default GPO configuration on the server side. This two aspects lowers the severity of the issue to Moderate.
Red Hat mitigation
A mitigation can be applied to the sssd.conf file that would make the occurrence of the race condition more difficult: 1. Increase the GPO cache time out editing the following configuration directive in sssd.conf file: a) ad_gpo_cache_timeout = 3600 Ps.: This value (3600) should make the cache time out in one hour but would make GPO updates propagation from AD server to local machines take longer. [1] https://access.redhat.com/documentation/pt-br/red_hat_enterprise_linux/7/html/windows_integration_guide/sssd-gpo
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 6, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.03% (0.01033) | 62.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.03% (0.01033) | 59.15th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.21% (0.00207) | 40.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.00th | v3 (v2023.03.01) |
| Jun 6, 2024 | 0.04% (0.00045) | 14.03th | v3 (v2023.03.01) |
| Apr 25, 2024 | 0.04% (0.00044) | 12.01th | v3 (v2023.03.01) |
| Apr 19, 2024 | 0.04% (0.00044) | 9.53th | v3 (v2023.03.01) |
References (15)
- https://access.redhat.com/errata/RHSA-2024:1919 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1920 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1921 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1922 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2571 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:3270 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-3758 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2223762 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/SSSD/sssd/pull/7302 ExploitIssue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2025/02/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RV3HIZI3SURBUQKSOOL3XE64OOBQ2HTK/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEP62IDS7A55D5UHM6GH7QZ7SQFOAPVF/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XMORAO2BDDA5YX4ZLMXDZ7SM6KU47SY5/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3758
- https://www.cve.org/CVERecord?id=CVE-2023-3758
Change history (0)
No recorded changes yet.