Local Denial of Service Vulnerability in SSSD by Red Hat
CVE-2026-104037

5.5MEDIUM

What is CVE-2026-104037?

A local attacker can exploit a flaw in SSSD by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This can lead to an integer underflow and an out-of-bounds memory read, ultimately crashing the responder process and resulting in a denial of service (DoS) event. The vulnerability poses a risk to system stability and availability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.