Amazon Linux 2023 Security Advisory: ALAS2023-2025-1249
Advisory Released Date: 2025-10-27
Advisory Updated Date: 2025-10-27
Severity:
Important
Issue Overview:
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts. (CVE-2025-11561)
Affected Packages:
sssd
Issue Correction:
Run dnf update sssd --releasever 2023.9.20251027 or dnf update --advisory ALAS2023-2025-1249 --releasever 2023.9.20251027 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
sssd-dbus-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-common-pac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_certmap-2.9.4-1.amzn2023.0.3.aarch64
sssd-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_nss_idmap-2.9.4-1.amzn2023.0.3.aarch64
libipa_hbac-devel-2.9.4-1.amzn2023.0.3.aarch64
libsss_certmap-devel-2.9.4-1.amzn2023.0.3.aarch64
libsss_idmap-devel-2.9.4-1.amzn2023.0.3.aarch64
sssd-debugsource-2.9.4-1.amzn2023.0.3.aarch64
sssd-dbus-2.9.4-1.amzn2023.0.3.aarch64
sssd-tools-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-common-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-ldap-2.9.4-1.amzn2023.0.3.aarch64
sssd-krb5-2.9.4-1.amzn2023.0.3.aarch64
sssd-proxy-2.9.4-1.amzn2023.0.3.aarch64
sssd-krb5-common-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-krb5-common-2.9.4-1.amzn2023.0.3.aarch64
sssd-client-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-client-2.9.4-1.amzn2023.0.3.aarch64
sssd-proxy-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-tools-2.9.4-1.amzn2023.0.3.aarch64
sssd-common-2.9.4-1.amzn2023.0.3.aarch64
sssd-kcm-2.9.4-1.amzn2023.0.3.aarch64
sssd-ipa-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-common-pac-2.9.4-1.amzn2023.0.3.aarch64
libsss_simpleifp-devel-2.9.4-1.amzn2023.0.3.aarch64
libsss_nss_idmap-devel-2.9.4-1.amzn2023.0.3.aarch64
sssd-ipa-2.9.4-1.amzn2023.0.3.aarch64
sssd-kcm-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-ad-2.9.4-1.amzn2023.0.3.aarch64
sssd-ad-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_idmap-2.9.4-1.amzn2023.0.3.aarch64
libsss_autofs-2.9.4-1.amzn2023.0.3.aarch64
libipa_hbac-2.9.4-1.amzn2023.0.3.aarch64
libsss_sudo-2.9.4-1.amzn2023.0.3.aarch64
sssd-nfs-idmap-2.9.4-1.amzn2023.0.3.aarch64
sssd-winbind-idmap-2.9.4-1.amzn2023.0.3.aarch64
python3-libipa_hbac-2.9.4-1.amzn2023.0.3.aarch64
python3-sss-2.9.4-1.amzn2023.0.3.aarch64
sssd-idp-2.9.4-1.amzn2023.0.3.aarch64
python3-libsss_nss_idmap-2.9.4-1.amzn2023.0.3.aarch64
libsss_simpleifp-2.9.4-1.amzn2023.0.3.aarch64
python3-sss-murmur-2.9.4-1.amzn2023.0.3.aarch64
libsss_certmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-nfs-idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
python3-libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_simpleifp-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
python3-sss-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-idp-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_autofs-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-ldap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
libsss_sudo-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
python3-libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-2.9.4-1.amzn2023.0.3.aarch64
libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-krb5-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
sssd-winbind-idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
python3-sss-murmur-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
noarch:
python3-sssdconfig-2.9.4-1.amzn2023.0.3.noarch
src:
sssd-2.9.4-1.amzn2023.0.3.src
x86_64:
sssd-dbus-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-common-pac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_certmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-krb5-common-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_simpleifp-devel-2.9.4-1.amzn2023.0.3.x86_64
libsss_nss_idmap-devel-2.9.4-1.amzn2023.0.3.x86_64
sssd-dbus-2.9.4-1.amzn2023.0.3.x86_64
sssd-common-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-ad-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-krb5-common-2.9.4-1.amzn2023.0.3.x86_64
sssd-debugsource-2.9.4-1.amzn2023.0.3.x86_64
sssd-proxy-2.9.4-1.amzn2023.0.3.x86_64
sssd-kcm-2.9.4-1.amzn2023.0.3.x86_64
sssd-client-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_certmap-devel-2.9.4-1.amzn2023.0.3.x86_64
sssd-tools-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-client-2.9.4-1.amzn2023.0.3.x86_64
sssd-proxy-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-tools-2.9.4-1.amzn2023.0.3.x86_64
libipa_hbac-devel-2.9.4-1.amzn2023.0.3.x86_64
libsss_idmap-devel-2.9.4-1.amzn2023.0.3.x86_64
sssd-kcm-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-ipa-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_certmap-2.9.4-1.amzn2023.0.3.x86_64
sssd-ad-2.9.4-1.amzn2023.0.3.x86_64
sssd-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-common-pac-2.9.4-1.amzn2023.0.3.x86_64
sssd-ipa-2.9.4-1.amzn2023.0.3.x86_64
sssd-ldap-2.9.4-1.amzn2023.0.3.x86_64
sssd-common-2.9.4-1.amzn2023.0.3.x86_64
sssd-nfs-idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-krb5-2.9.4-1.amzn2023.0.3.x86_64
libsss_nss_idmap-2.9.4-1.amzn2023.0.3.x86_64
libsss_simpleifp-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
python3-libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_idmap-2.9.4-1.amzn2023.0.3.x86_64
python3-sss-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_autofs-2.9.4-1.amzn2023.0.3.x86_64
libsss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libipa_hbac-2.9.4-1.amzn2023.0.3.x86_64
sssd-idp-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_sudo-2.9.4-1.amzn2023.0.3.x86_64
libsss_autofs-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-nfs-idmap-2.9.4-1.amzn2023.0.3.x86_64
libsss_sudo-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
python3-sss-2.9.4-1.amzn2023.0.3.x86_64
python3-libipa_hbac-2.9.4-1.amzn2023.0.3.x86_64
sssd-ldap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libsss_simpleifp-2.9.4-1.amzn2023.0.3.x86_64
sssd-2.9.4-1.amzn2023.0.3.x86_64
python3-libsss_nss_idmap-2.9.4-1.amzn2023.0.3.x86_64
sssd-idp-2.9.4-1.amzn2023.0.3.x86_64
python3-libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
sssd-krb5-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
python3-sss-murmur-2.9.4-1.amzn2023.0.3.x86_64
sssd-winbind-idmap-2.9.4-1.amzn2023.0.3.x86_64
sssd-winbind-idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
python3-sss-murmur-debuginfo-2.9.4-1.amzn2023.0.3.x86_64