Denial of Service Vulnerability in SSSD by Red Hat
CVE-2026-88252

4.7MEDIUM

What is CVE-2026-88252?

A significant flaw exists in the System Security Services Daemon (SSSD) that enables a local user to initiate a Denial of Service (DoS) attack. By opening multiple concurrent connections to a responder socket while continuously queuing new connection requests, an attacker can exhaust the available file descriptors used by the responder service. This behavior results in high CPU utilization and ultimately stalls the service, preventing legitimate identity and authentication requests from being processed effectively.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.