Impact
A flaw in the System Security Services Daemon allows a local user to trigger a denial of service by submitting a specially crafted passkey authentication token without null terminators. The library reads past the end of the supplied memory buffer, leading to a crash of the authentication process and a disruption of authentication services. The weakness is a classic out‑of‑bounds read identified as CWE‑125.
Affected Systems
This issue affects Red Hat products including Red Hat Enterprise Linux versions 6 through 10 and Red Hat OpenShift Container Platform 4. Specific patch numbers and version ranges are not disclosed in the current data, so any system running these products with the vulnerable sssd component should be considered at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. No EPSS value is provided and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation evidence. However, the flaw is exploitable locally and does not require network access, so any user with privileges to submit authentication tokens can trigger the crash. The local nature and lack of remote execution make it a denial‑of‑service weakness rather than an elevation or data‑exfiltration risk.
OpenCVE Enrichment