Description
A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS).
Published: 2026-10-06
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in SSSD causes memory allocated during processing of autofs requests to be retained until the client connection is closed. A local attacker who can maintain an open connection and repeatedly issue valid autofs requests can exhaust system memory, causing the service to become unresponsive. This issue is classified as an unreleased resource flaw (CWE‑772).

Affected Systems

Red Hat Enterprise Linux 6, 7, 8, 9, 10 and Red Hat OpenShift Container Platform 4 are affected when the autofs responder service is enabled. The vulnerability is present in the SSSD component of these systems.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is local; a privileged or local user must be able to open a connection to the autofs responder. Successful exploitation leads to memory exhaustion and a denial of service, impacting availability for the affected service and potentially other services sharing the same host resources.

Generated by OpenCVE AI on October 6, 2026 at 01:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Red Hat security updates that include the fixed SSSD autofs responder patch via the standard RHEL and OpenShift update channels.
  • If an update cannot be applied immediately, disable or restrict the autofs responder component so that only trusted local users can access it, thereby preventing persistent connections that could consume memory.
  • Configure SSSD or the underlying operating system to limit concurrent autofs requests or enforce memory quotas, following Red Hat guidance on resource management for services that allocate per‑connection memory.

Generated by OpenCVE AI on October 6, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS).
Title Sssd: sssd: denial of service via memory exhaustion in autofs responder
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-772
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T00:10:37.592Z

Reserved: 2026-10-01T17:20:25.333Z

Link: CVE-2026-104031

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T01:16:33.843

Modified: 2026-10-06T01:16:33.843

Link: CVE-2026-104031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T01:30:09Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime