Description
A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed.
Published: 2026-10-06
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service to authentication services via file descriptor exhaustion
Action: Apply Update
AI Analysis

Impact

A local user can cause a denial of service by exhausting the responder service’s file descriptors. By opening many concurrent connections and continuing to queue new attempts, the attacker forces an unthrottled retry loop that consumes CPU and stalls sssd, preventing legitimate identity and authentication requests from being processed.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux releases 6 through 10 and Red Hat OpenShift Container Platform 4. No specific sub‑versions are listed, so all current installations of these products are potentially impacted.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity vulnerability. The EPSS score is not available and the issue is not listed in CISA KEV, suggesting that commercial exploitation is not yet observed. The intent of the attack is local; an attacker must be able to run user processes to initiate many connections to the responder socket. Successful exploitation leads to high CPU usage and a service outage, but it does not compromise confidentiality or integrity of data.

Generated by OpenCVE AI on October 6, 2026 at 19:47 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Install the latest Red Hat update for sssd as soon as it is released.
  • Configure system limits or firewall rules to restrict the number of concurrent connections to the responder port, thereby reducing the likelihood of file descriptor exhaustion.
  • Set up monitoring of CPU utilization and file descriptor counts; automatically restart the sssd service when thresholds are exceeded.

Generated by OpenCVE AI on October 6, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed.
Title Sssd: sssd: denial of service via responder connection retry loop during file descriptor exhaustion
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-835
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T18:21:02.040Z

Reserved: 2026-09-09T22:49:08.240Z

Link: CVE-2026-88252

cve-icon Vulnrichment

Updated: 2026-10-06T18:20:54.142Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:56.867

Modified: 2026-10-06T20:05:39.400

Link: CVE-2026-88252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:00:06Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')