Local Attacker Exploits Integer Underflow in SSSD by Manipulating NSS Responder Socket
CVE-2026-104043

5.5MEDIUM

What is CVE-2026-104043?

An integer underflow flaw exists in SSSD that allows a local attacker with access to the Name Service Switch (NSS) responder UNIX socket to exploit this vulnerability. By sending specially crafted requests containing undersized packet headers, an attacker can trigger an out-of-bounds memory read during the parsing of packets. This results in a crash of the responder process, leading to a Denial of Service (DoS) condition that can disrupt service availability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.