Impact
A flaw was identified in the System Security Services Daemon (SSSD). In the NSS responder, the function that prepares the initial group list pre‑allocates memory for all possible group entries but fails to reduce the packet size when some groups are omitted. This oversight allows uninitialized heap bytes to be sent to a client. A local attacker who can reach the sssd_nss process can read confidential directory data and obtain details about the heap layout, which could aid further attacks. The weakness corresponds to CWE‑908, indicating that uninitialized memory was leaked.
Affected Systems
The vulnerability impacts Red Hat Enterprise Linux versions 6, 7, 8, 9, and 10, as well as Red Hat OpenShift Container Platform 4. Systems running the SSSD NSS responder on any of these platforms without the latest update are potentially exposed.
Risk and Exploitability
The CVSS score of 3.3 suggests a low severity impact when viewed globally, and the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not cataloged in CISA's KEV list, indicating no confirmed field‑deployed exploitation as of the latest data. Attackers must be able to access the local sssd_nss process, so the attack vector is local; the exploit does not require network or privilege escalation. Due to the low severity rating and lack of known exploitation, the risk is considered moderate if the affected system is exposed to local attackers. However, the ability to recover sensitive information, especially directory contents, elevates the concern for any trusted environment.
OpenCVE Enrichment