Impact
A local input‑validation flaw exists in the sssd NSS responder. A malicious user can send crafted service lookup requests to the responder’s UNIX socket, causing a buffer underrun read that may crash the process. The vulnerability does not provide privilege escalation or reliable data disclosure, but it does allow an attacker to repeatedly terminate the NSS responder, impairing name‑service resolution for local processes.
Affected Systems
The flaw affects all Red Hat Enterprise Linux releases 6 through 9 and the Red Hat OpenShift Container Platform 4 distribution. Systems running these operating environments with the sssd NSS responder active are susceptible.
Risk and Exploitability
The CVSS score of 4.0 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; unprivileged users can normally reach the UNIX socket, so an attacker must have local access. Because the effect is a denial of service rather than data exposure, the overall risk is confined to service disruption.
OpenCVE Enrichment