Description
A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.
Published: 2026-09-14
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via out-of-bounds read
Action: Apply Workaround
AI Analysis

Impact

A local input‑validation flaw exists in the sssd NSS responder. A malicious user can send crafted service lookup requests to the responder’s UNIX socket, causing a buffer underrun read that may crash the process. The vulnerability does not provide privilege escalation or reliable data disclosure, but it does allow an attacker to repeatedly terminate the NSS responder, impairing name‑service resolution for local processes.

Affected Systems

The flaw affects all Red Hat Enterprise Linux releases 6 through 9 and the Red Hat OpenShift Container Platform 4 distribution. Systems running these operating environments with the sssd NSS responder active are susceptible.

Risk and Exploitability

The CVSS score of 4.0 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; unprivileged users can normally reach the UNIX socket, so an attacker must have local access. Because the effect is a denial of service rather than data exposure, the overall risk is confined to service disruption.

Generated by OpenCVE AI on September 15, 2026 at 13:23 UTC.

Remediation

Vendor Workaround

There's no appropriated mitigation for this issue.


OpenCVE Recommended Actions

  • Restrict local access to the SSSD NSS responder UNIX socket (`/var/lib/sss/pipes/nss`) by setting strict file permissions or enforcing UID restrictions, which reduces the attack surface but does not fix the parser bug.
  • After changing the socket permissions, restart the SSSD service so the new rules take effect.
  • Continuously monitor system logs for NSS responder crashes, ensuring the socket remains protected, and check for any vendor‑issued patch; when available, apply the official upgrade to fully remove the vulnerability.

Generated by OpenCVE AI on September 15, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.
Title Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-125
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T14:47:50.569Z

Reserved: 2026-09-11T22:08:46.106Z

Link: CVE-2026-90463

cve-icon Vulnrichment

Updated: 2026-09-14T16:45:07.764Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T16:17:23.400

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-90463

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-14T13:53:00Z

Links: CVE-2026-90463 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:30:13Z

Weaknesses