Impact
A local user can cause a denial of service by exhausting the responder service’s file descriptors. By opening many concurrent connections and continuing to queue new attempts, the attacker forces an unthrottled retry loop that consumes CPU and stalls sssd, preventing legitimate identity and authentication requests from being processed.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6 through 10 and Red Hat OpenShift Container Platform 4. No specific sub‑versions are listed, so all current installations of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity vulnerability. The EPSS score is not available and the issue is not listed in CISA KEV, suggesting that commercial exploitation is not yet observed. The intent of the attack is local; an attacker must be able to run user processes to initiate many connections to the responder socket. Successful exploitation leads to high CPU usage and a service outage, but it does not compromise confidentiality or integrity of data.
OpenCVE Enrichment