Description
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Published: 2026-08-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the extract_authtok_v1() function of the SSSD PAM responder, where the auth_token_length field is not validated against the remaining buffer size before processing. A crafted protocol v1 request can trigger an out‑of‑bounds read, causing the PAM responder to crash. The resulting crash leads to a denial of service, interrupting authentication services that depend on SSSD.

Affected Systems

Those running the System Security Services Daemon (SSSD) on Linux distributions are affected. The CVE record does not specify affected SSSD or OS versions, so any installation of SSSD that implements the vulnerable function is potentially impacted.

Risk and Exploitability

The CVSS score of 5.5 classifies the vulnerability as moderate. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild. The attack requires a local attacker with the ability to send a crafted request to the PAM responder socket, after which the service will crash and halt authentication processes.

Generated by OpenCVE AI on August 4, 2026 at 09:05 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Upgrade to a SSSD version that contains the fix for the auth_token_length validation bug.
  • Restrict access to the PAM responder socket to legitimate processes and users to reduce the likelihood that a local attacker can craft the malicious request.
  • Monitor PAM responder logs for repeated crashes or abnormal activity and apply any available vendor advisories or security patches promptly.

Generated by OpenCVE AI on August 4, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject sssd
Redhat openshift Container Platform
CPEs cpe:2.3:a:fedoraproject:sssd:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject sssd
Redhat openshift Container Platform

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title sssd: sssd: PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Mon, 03 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Sssd
Sssd sssd
Vendors & Products Sssd
Sssd sssd

Mon, 03 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Title sssd: sssd: PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Subscriptions

Fedoraproject Sssd
Redhat Enterprise Linux Openshift Openshift Container Platform
Sssd Sssd
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-04T19:10:51.243Z

Reserved: 2026-07-31T12:44:34.409Z

Link: CVE-2026-68743

cve-icon Vulnrichment

Updated: 2026-08-04T19:10:19.852Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T19:16:53.467

Modified: 2026-08-17T13:10:02.357

Link: CVE-2026-68743

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-03T07:34:52Z

Links: CVE-2026-68743 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:15:03Z

Weaknesses