stable

sssd-2.11.1-2.fc42

FEDORA-2025-5f49ddd4af created by atikhonov 4 months ago for Fedora 42

After startup SSSD already creates a Kerberos configuration snippet in /var/lib/sss/pubconf/krb5.include.d/localauth_plugin if the AD or IPA providers are used. This enables SSSD's localauth plugin. Starting with this update the an2ln plugin is disabled in the configuration snippet as well. If this file or its content are included in the Kerberos configuration (a default on Fedora) it will fix CVE-2025-11561.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-5f49ddd4af

This update has been submitted for testing by atikhonov.

4 months ago

This update's test gating status has been changed to 'waiting'.

4 months ago

This update's test gating status has been changed to 'failed'.

4 months ago

This update's test gating status has been changed to 'passed'.

4 months ago
User Icon fredrik commented & provided feedback 4 months ago
karma

No errors observed. Silverblue 42.20251020.0

This update has been pushed to testing.

4 months ago
User Icon filiperosset commented & provided feedback 4 months ago
karma

no regressions noted

This update can be pushed to stable now if the maintainer wishes

4 months ago
karma

This update has been submitted for stable by bodhi.

4 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
4 months ago
in testing
4 months ago
in stable
3 months ago
approved
4 months ago

Automated Test Results