Linuxsecurity
SUSE Linux Micro Updates Address Critical Privilege Escalation Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SUSE Linux Micro has released important updates addressing two critical vulnerabilities in the sssd and pam components. CVE-2026-14474 allows privilege escalation through the sudo LDAP provider, while CVE-2026-14476 permits Kerberos authentication bypass via path traversal. Both vulnerabilities were published on July 7, 2026, and have been assigned high CVSS scores of 8.8 and 8.0, respectively. Additionally, a moderate vulnerability, CVE-2026-54411, in the pam_userdb module was disclosed, which involves a timing discrepancy in password comparison. Users of SUSE Linux Micro 6.0 are urged to apply the patches immediately to mitigate risks. The updates can be installed using SUSE's recommended methods, including YaST online_update or zypper patch. The vulnerabilities affect various architectures, including aarch64, s390x, and x86_64. Current status indicates that these vulnerabilities are now patched, but administrators must act promptly to secure their systems.
Key Points: • Two critical vulnerabilities in sssd allow privilege escalation and Kerberos bypass. • CVE-2026-14474 and CVE-2026-14476 were published on July 7, 2026, with high CVSS scores. • A moderate vulnerability in pam affects password comparison, requiring immediate patching.