Impact
A flaw in SSSD causes memory allocated during processing of autofs requests to be retained until the client connection is closed. A local attacker who can maintain an open connection and repeatedly issue valid autofs requests can exhaust system memory, causing the service to become unresponsive. This issue is classified as an unreleased resource flaw (CWE‑772).
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9, 10 and Red Hat OpenShift Container Platform 4 are affected when the autofs responder service is enabled. The vulnerability is present in the SSSD component of these systems.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is local; a privileged or local user must be able to open a connection to the autofs responder. Successful exploitation leads to memory exhaustion and a denial of service, impacting availability for the affected service and potentially other services sharing the same host resources.
OpenCVE Enrichment