---
title: "CVE-2023-3758\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-3758?format=md
keywords: index, follow
---

# CVE-2023-3758

Publication date 18 April 2024

Last updated 19 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2023-3758?format=md#impact-score)

Toggle side navigation

## Description

A race condition flaw was found in sssd where the GPO policy is not
consistently applied for authenticated users. This may lead to improper
authorization issues, granting or denying access to resources
inappropriately.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| sssd | 26.04 LTS resolute | Fixed 2.9.4-1.1ubuntu7 |
| 25.10 questing | Fixed 2.9.4-1.1ubuntu7 |
| 25.04 plucky | Fixed 2.9.4-1.1ubuntu7 |
| 24.10 oracular | Fixed 2.9.4-1.1ubuntu7 |
| 24.04 LTS noble | Fixed 2.9.4-1.1ubuntu6.1 |
| 23.10 mantic | Fixed 2.9.1-2ubuntu2.1 |
| 22.04 LTS jammy | Fixed 2.6.3-1ubuntu3.3 |
| 20.04 LTS focal | Fixed 2.2.3-3ubuntu0.13 |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2023-3758?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| sssd | * Upstream:   [d7db797](https://github.com/SSSD/sssd/commit/d7db7971682da2dbf7642ac94940d6b0577ec35a) * Upstream:   [e1bfbc2](https://github.com/SSSD/sssd/commit/e1bfbc2493c4194988acc3b2413df3dde0735ae3) * Upstream:   [f4ebe14](https://github.com/SSSD/sssd/commit/f4ebe1408e0bc67abfbfb5f0ca2ea13803b36726) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Adjacent |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3758)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-3758)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-3758)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-3758)

### Related Ubuntu Security Notices (USN)

+ [USN-6836-1](https://usn.ubuntu.com/USN-6836-1)
+ SSSD vulnerability
+ 17 June 2024

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2023-3758>
* <https://github.com/SSSD/sssd/pull/7302>
* <https://access.redhat.com/errata/RHSA-2024:1919>
* <https://access.redhat.com/errata/RHSA-2024:1920>
* <https://access.redhat.com/errata/RHSA-2024:1921>
* <https://access.redhat.com/errata/RHSA-2024:1922>
* <https://access.redhat.com/security/cve/CVE-2023-3758>
