Denial of Service Vulnerability in sssd-kcm Affecting Red Hat Products
CVE-2026-80048
Currently unrated
What is CVE-2026-80048?
A vulnerability exists in the sssd-kcm component, allowing a local user or process to exploit the UNIX socket. By manipulating the request length header and stalling the connection, an attacker can induce extensive memory preallocation. This exploitation leads to significant memory exhaustion in the sssd-kcm responder, ultimately resulting in a Denial of Service condition for the impacted systems, disrupting normal operations and access.