Buffer Overflow in SSSD Affects Red Hat Enterprise Linux
CVE-2026-104029

3.3LOW

What is CVE-2026-104029?

A vulnerability was identified in SSSD, where a local attacker can exploit the system by sending a maliciously crafted request to the autofs responder UNIX socket. This exploitation stems from improper buffer offset calculations during the parsing of requests. As a result, the service may encounter an out-of-bounds memory read, potentially leading to the autofs responder process crashing. The exploitation of this flaw can consequently result in a denial of service (DoS) on the affected system.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.