ALAS2023-2025-1249


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1249
Advisory Released Date: 2025-10-27
Advisory Updated Date: 2025-10-27
Severity: Important

Issue Overview:

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts. (CVE-2025-11561)


Affected Packages:

sssd


Issue Correction:
Run dnf update sssd --releasever 2023.9.20251027 or dnf update --advisory ALAS2023-2025-1249 --releasever 2023.9.20251027 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    sssd-dbus-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-common-pac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_certmap-2.9.4-1.amzn2023.0.3.aarch64
    sssd-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_nss_idmap-2.9.4-1.amzn2023.0.3.aarch64
    libipa_hbac-devel-2.9.4-1.amzn2023.0.3.aarch64
    libsss_certmap-devel-2.9.4-1.amzn2023.0.3.aarch64
    libsss_idmap-devel-2.9.4-1.amzn2023.0.3.aarch64
    sssd-debugsource-2.9.4-1.amzn2023.0.3.aarch64
    sssd-dbus-2.9.4-1.amzn2023.0.3.aarch64
    sssd-tools-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-common-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ldap-2.9.4-1.amzn2023.0.3.aarch64
    sssd-krb5-2.9.4-1.amzn2023.0.3.aarch64
    sssd-proxy-2.9.4-1.amzn2023.0.3.aarch64
    sssd-krb5-common-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-krb5-common-2.9.4-1.amzn2023.0.3.aarch64
    sssd-client-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-client-2.9.4-1.amzn2023.0.3.aarch64
    sssd-proxy-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-tools-2.9.4-1.amzn2023.0.3.aarch64
    sssd-common-2.9.4-1.amzn2023.0.3.aarch64
    sssd-kcm-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ipa-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-common-pac-2.9.4-1.amzn2023.0.3.aarch64
    libsss_simpleifp-devel-2.9.4-1.amzn2023.0.3.aarch64
    libsss_nss_idmap-devel-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ipa-2.9.4-1.amzn2023.0.3.aarch64
    sssd-kcm-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ad-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ad-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_idmap-2.9.4-1.amzn2023.0.3.aarch64
    libsss_autofs-2.9.4-1.amzn2023.0.3.aarch64
    libipa_hbac-2.9.4-1.amzn2023.0.3.aarch64
    libsss_sudo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-nfs-idmap-2.9.4-1.amzn2023.0.3.aarch64
    sssd-winbind-idmap-2.9.4-1.amzn2023.0.3.aarch64
    python3-libipa_hbac-2.9.4-1.amzn2023.0.3.aarch64
    python3-sss-2.9.4-1.amzn2023.0.3.aarch64
    sssd-idp-2.9.4-1.amzn2023.0.3.aarch64
    python3-libsss_nss_idmap-2.9.4-1.amzn2023.0.3.aarch64
    libsss_simpleifp-2.9.4-1.amzn2023.0.3.aarch64
    python3-sss-murmur-2.9.4-1.amzn2023.0.3.aarch64
    libsss_certmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-nfs-idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    python3-libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_simpleifp-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    python3-sss-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-idp-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_autofs-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-ldap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    libsss_sudo-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    python3-libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-2.9.4-1.amzn2023.0.3.aarch64
    libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-krb5-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    sssd-winbind-idmap-debuginfo-2.9.4-1.amzn2023.0.3.aarch64
    python3-sss-murmur-debuginfo-2.9.4-1.amzn2023.0.3.aarch64

noarch:
    python3-sssdconfig-2.9.4-1.amzn2023.0.3.noarch

src:
    sssd-2.9.4-1.amzn2023.0.3.src

x86_64:
    sssd-dbus-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-common-pac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_certmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-krb5-common-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_simpleifp-devel-2.9.4-1.amzn2023.0.3.x86_64
    libsss_nss_idmap-devel-2.9.4-1.amzn2023.0.3.x86_64
    sssd-dbus-2.9.4-1.amzn2023.0.3.x86_64
    sssd-common-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ad-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-krb5-common-2.9.4-1.amzn2023.0.3.x86_64
    sssd-debugsource-2.9.4-1.amzn2023.0.3.x86_64
    sssd-proxy-2.9.4-1.amzn2023.0.3.x86_64
    sssd-kcm-2.9.4-1.amzn2023.0.3.x86_64
    sssd-client-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_certmap-devel-2.9.4-1.amzn2023.0.3.x86_64
    sssd-tools-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-client-2.9.4-1.amzn2023.0.3.x86_64
    sssd-proxy-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-tools-2.9.4-1.amzn2023.0.3.x86_64
    libipa_hbac-devel-2.9.4-1.amzn2023.0.3.x86_64
    libsss_idmap-devel-2.9.4-1.amzn2023.0.3.x86_64
    sssd-kcm-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ipa-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_certmap-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ad-2.9.4-1.amzn2023.0.3.x86_64
    sssd-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-common-pac-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ipa-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ldap-2.9.4-1.amzn2023.0.3.x86_64
    sssd-common-2.9.4-1.amzn2023.0.3.x86_64
    sssd-nfs-idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-krb5-2.9.4-1.amzn2023.0.3.x86_64
    libsss_nss_idmap-2.9.4-1.amzn2023.0.3.x86_64
    libsss_simpleifp-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    python3-libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_idmap-2.9.4-1.amzn2023.0.3.x86_64
    python3-sss-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_autofs-2.9.4-1.amzn2023.0.3.x86_64
    libsss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libipa_hbac-2.9.4-1.amzn2023.0.3.x86_64
    sssd-idp-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_sudo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_autofs-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-nfs-idmap-2.9.4-1.amzn2023.0.3.x86_64
    libsss_sudo-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    python3-sss-2.9.4-1.amzn2023.0.3.x86_64
    python3-libipa_hbac-2.9.4-1.amzn2023.0.3.x86_64
    sssd-ldap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libsss_simpleifp-2.9.4-1.amzn2023.0.3.x86_64
    sssd-2.9.4-1.amzn2023.0.3.x86_64
    python3-libsss_nss_idmap-2.9.4-1.amzn2023.0.3.x86_64
    sssd-idp-2.9.4-1.amzn2023.0.3.x86_64
    python3-libsss_nss_idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    libipa_hbac-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    sssd-krb5-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    python3-sss-murmur-2.9.4-1.amzn2023.0.3.x86_64
    sssd-winbind-idmap-2.9.4-1.amzn2023.0.3.x86_64
    sssd-winbind-idmap-debuginfo-2.9.4-1.amzn2023.0.3.x86_64
    python3-sss-murmur-debuginfo-2.9.4-1.amzn2023.0.3.x86_64