Use-After-Free Vulnerability in SSSD Affecting Authentication Processes with YubiKey
CVE-2026-12610

6.4MEDIUM

What is CVE-2026-12610?

A notable vulnerability exists in SSSD, specifically when authenticating with a YubiKey. This use-after-free vulnerability occurs due to improper handling of a memory pointer during the authentication process, potentially leading to a crash of the SSSD PAM responder. A local attacker could exploit this vulnerability by altering the contents of a smartcard or YubiKey, which could result in a denial of service that hampers authentication capabilities. While there is a theoretical risk for privilege escalation, the conditions to successfully exploit this aspect are considerably challenging.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.