Heap Information Disclosure Vulnerability in SSSD NSS Responder by Red Hat
CVE-2026-68744

3.3LOW

What is CVE-2026-68744?

A vulnerability exists in the System Security Services Daemon (SSSD) within the name service switch (NSS) responder. The affected function, sss_nss_protocol_fill_initgr(), improperly manages reply space for group entries. Specifically, it fails to reduce the size of the packet when certain groups are not returned, resulting in the exposure of uninitialized bytes from the heap. This flaw can be exploited by a local attacker to access sensitive cached directory data and gain insights into the heap layout of the sssd_nss process, potentially compromising system security.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Vivek Parikh (BreachX Zero Day Labs) for reporting this issue.
.