New Debian sssd 2.8.2-4+deb12u1A~5.2.1.202503241535 fixes: This update addresses the following issue: * sssd: Race condition during authorization leads to GPO policies functioning inconsistently (CVE-2023-3758)
--- mirror/ftp/pool/main/s/sssd/sssd_2.8.2-4A~5.2.0.202403161526.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/sssd_2.8.2-4+deb12u1A~5.2.1.202503241535.dsc @@ -1,7 +1,16 @@ -2.8.2-4A~5.2.0.202403161526 [Sat, 16 Mar 2024 15:26:23 +0100] Univention builddaemon <buildd@univention.de>: +2.8.2-4+deb12u1A~5.2.1.202503241535 [Mon, 24 Mar 2025 15:36:24 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 10_fix_pam_auth_for_simpleldapaccounts.quilt + +2.8.2-4+deb12u1 [Sun, 09 Feb 2025 11:45:11 +0100] Guilhem Moulin <guilhem@debian.org>: + + * Non-maintainer upload. + * Fix CVE-2023-3758: Due to a race condition flaw the GPO policy is not + consistently applied for authenticated users. (Closes: #1070369) + * Add d/.gitlab-ci.yml for Salsa CI. + * Add d/.gitignore file to exclude d/p/*.patch from upstream gitignore(5)'d + rules. 2.8.2-4 [Tue, 11 Apr 2023 15:19:36 +0300] Timo Aaltonen <tjaalton@debian.org>: <http://piuparts.knut.univention.de/5.2-1/#7655176137406224853>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] 21a65b53ce1 Bug #58107: sssd 2.8.2-4+deb12u1A~5.2.1.202503241535 doc/errata/staging/sssd.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x50>