Local Denial of Service Vulnerability in SSSD by Red Hat
CVE-2026-104037
5.5MEDIUM
What is CVE-2026-104037?
A local attacker can exploit a flaw in SSSD by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This can lead to an integer underflow and an out-of-bounds memory read, ultimately crashing the responder process and resulting in a denial of service (DoS) event. The vulnerability poses a risk to system stability and availability.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.