Impact
A flaw in the SSSD autofs responder causes an out‑of‑bounds memory read when it parses a crafted request sent to its UNIX socket. The read can crash the autofs responder process, leading to a denial of service for services that rely on it. The vulnerability is limited to a local attacker who can reach the socket, and it does not provide lateral movement or data exfiltration.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 10, 6, 7, 8, 9, and Red Hat OpenShift Container Platform 4. Specific version numbers are not provided in the advisory, so the issue is presumed to exist in all released releases of these products until a fix is applied.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score is not available, suggesting no known widespread exploitation. The vulnerability is listed as not in the CISA KEV catalog. An attacker would need local access to craft a request to the autofs responder socket; with such access the attacker can induce service crashes but cannot compromise other components or obtain data.
OpenCVE Enrichment