Description
A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS).
Published: 2026-10-06
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via use‑after‑free in Kerberos Credential Manager during ticket renewal
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free flaw in the Kerberos Credential Manager responder of SSSD was discovered. The vulnerability occurs during ticket‑granting ticket renewal when a deferred callback accesses memory that has already been freed, allowing an authenticated local user possessing a renewable Kerberos ticket to cause the responder service to crash. The crash results in a denial of service that can interrupt authentication services on the affected host.

Affected Systems

The flaw affects multiple Red Hat ecosystems, including Red Hat Enterprise Linux releases 6 through 10 and the Red Hat OpenShift Container Platform 4. All configurations that enable KCM ticket renewal on these platforms are vulnerable. Specific package versions are not enumerated in the advisory.

Risk and Exploitability

The CVSS base score of 4.7 indicates a moderate severity, and the vulnerability requires local authentication with a renewable Kerberos ticket to be exercised, making exploitation unlikely against anonymous users. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation risk. Nevertheless, the potential for a service crash suggests that affected systems should be considered within a higher risk posture while a patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all affected Red Hat Enterprise Linux and OpenShift installations to the latest available package version that contains the fix for CVE‑2026‑104034 (consult the vendor's advisory for the specific update).
  • If an immediate update is not possible, disable Kerberos Credential Manager ticket renewal by removing or commenting out the renew_interval setting in the SSSD configuration, which stops the vulnerable callback from being scheduled.
  • Review local user accounts to ensure they are not granted renewable Kerberos tickets unless absolutely necessary, thereby limiting the attack surface for this vulnerability.

Generated by OpenCVE AI on October 6, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS).
Title Sssd: sssd: denial of service via use-after-free in kcm ticket renewal
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-825
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T00:12:17.976Z

Reserved: 2026-10-01T17:21:33.512Z

Link: CVE-2026-104034

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T01:16:34.273

Modified: 2026-10-06T01:16:34.273

Link: CVE-2026-104034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T01:30:09Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference