Description
A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS).
Published: 2026-10-05
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the SSSD autofs responder causes an out‑of‑bounds memory read when it parses a crafted request sent to its UNIX socket. The read can crash the autofs responder process, leading to a denial of service for services that rely on it. The vulnerability is limited to a local attacker who can reach the socket, and it does not provide lateral movement or data exfiltration.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 10, 6, 7, 8, 9, and Red Hat OpenShift Container Platform 4. Specific version numbers are not provided in the advisory, so the issue is presumed to exist in all released releases of these products until a fix is applied.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, and the EPSS score is not available, suggesting no known widespread exploitation. The vulnerability is listed as not in the CISA KEV catalog. An attacker would need local access to craft a request to the autofs responder socket; with such access the attacker can induce service crashes but cannot compromise other components or obtain data.

Generated by OpenCVE AI on October 5, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SSSD package to the latest patched version available from Red Hat.
  • After installing the update, restart the SSSD service to load the corrected code.
  • Verify that the autofs responder UNIX socket is only accessible by trusted users or services, and consider disabling autofs if not required.

Generated by OpenCVE AI on October 5, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS).
Title Sssd: sssd: denial of service via out-of-bounds read in autofs responder
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-125
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-05T19:13:50.965Z

Reserved: 2026-10-01T17:19:41.021Z

Link: CVE-2026-104029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:08.487

Modified: 2026-10-05T20:17:08.487

Link: CVE-2026-104029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses