Memory Exhaustion Vulnerability in SSSD by Red Hat
CVE-2026-104041

5.5MEDIUM

What is CVE-2026-104041?

A vulnerability exists in SSSD that allows unprivileged local users to exploit the Name Service Switch (NSS) responder. By sending repeated requests for nonexistent entries, users can fill the negative cache, which does not limit the number of stored entries. This can lead to memory exhaustion as the responder grows unresponsive or crashes due to overwhelming requests. The absence of bounds on cache storage exacerbates the potential for Denial of Service, affecting system availability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.