Use-After-Free Vulnerability in SSSD Affecting Authentication Processes with YubiKey
CVE-2026-12610
6.4MEDIUM
What is CVE-2026-12610?
A notable vulnerability exists in SSSD, specifically when authenticating with a YubiKey. This use-after-free vulnerability occurs due to improper handling of a memory pointer during the authentication process, potentially leading to a crash of the SSSD PAM responder. A local attacker could exploit this vulnerability by altering the contents of a smartcard or YubiKey, which could result in a denial of service that hampers authentication capabilities. While there is a theoretical risk for privilege escalation, the conditions to successfully exploit this aspect are considerably challenging.