Denial of Service Vulnerability in sssd by Red Hat
CVE-2026-104030
5.5MEDIUM
What is CVE-2026-104030?
A vulnerability in sssd allows a local user to trigger a Denial of Service condition by providing a malformed passkey authentication token that lacks proper null terminators. This misconfiguration leads to the authentication service reading beyond the allocated memory buffer, which can crash the process and disrupt authentication services for other users.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.