Input Validation Flaw in NSS Responder of Red Hat Products
CVE-2026-90463
4MEDIUM
What is CVE-2026-90463?
A security flaw discovered in the NSS responder of Red Hat products enables local attackers to exploit input validation issues. By crafting specific service lookup requests and targeting the NSS responder’s UNIX socket, an attacker can trigger an out-of-bounds read. This can result in a denial of service by crashing the NSS responder process. Although unprivileged local clients can typically interact with the socket, there is no indication that this vulnerability allows for privilege escalation or reliable data leakage.
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.