A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.
https://pagure.io/SSSD/sssd/issue/1470
https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-3422