SUSE Linux Micro Updates Address Critical Privilege Escalation Vulnerabilities

SUSE Linux Micro Updates Address Critical Privilege Escalation Vulnerabilities

First seen 27 Jul 2026, 19:52 UTC Linuxsecurity 72% similarity 74.0

Article Content

Browse articles
ThreatCluster

SUSE Linux Micro has released important updates addressing two critical vulnerabilities in the sssd and pam components. CVE-2026-14474 allows privilege escalation through the sudo LDAP provider, while CVE-2026-14476 permits Kerberos authentication bypass via path traversal. Both vulnerabilities were published on July 7, 2026, and have been assigned high CVSS scores of 8.8 and 8.0, respectively. Additionally, a moderate vulnerability, CVE-2026-54411, in the pam_userdb module was disclosed, which involves a timing discrepancy in password comparison. Users of SUSE Linux Micro 6.0 are urged to apply the patches immediately to mitigate risks. The updates can be installed using SUSE's recommended methods, including YaST online_update or zypper patch. The vulnerabilities affect various architectures, including aarch64, s390x, and x86_64. Current status indicates that these vulnerabilities are now patched, but administrators must act promptly to secure their systems.

Key Points: • Two critical vulnerabilities in sssd allow privilege escalation and Kerberos bypass. • CVE-2026-14474 and CVE-2026-14476 were published on July 7, 2026, with high CVSS scores. • A moderate vulnerability in pam affects password comparison, requiring immediate patching.

ThreatCluster AI How this analysis works

Timeline

2026-06-14
CVE-2026-54411 published
A timing discrepancy in pam_userdb module's password comparison was disclosed, affecting SUSE Linux Micro.
Linuxsecurity
2026-07-07
CVE-2026-14474 and CVE-2026-14476 published
Critical vulnerabilities in sssd were disclosed, enabling privilege escalation and Kerberos authentication bypass.
Linuxsecurity
2026-07-17
SUSE releases patch for sssd vulnerabilities
SUSE issued an important update for sssd addressing CVE-2026-14474 and CVE-2026-14476, urging users to patch.
Linuxsecurity
2026-07-22
SUSE releases patch for pam vulnerability
An update for pam was released to fix CVE-2026-54411, addressing the timing discrepancy issue.
Linuxsecurity
2026-07-27
Current status of vulnerabilities
All identified vulnerabilities in SUSE Linux Micro have been patched, but immediate action is recommended for users.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story