Description
A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.
Published: 2026-09-14
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Implement Workaround
AI Analysis

Impact

A flaw was discovered in the PAM responder's protocol v1 parser in sssd, allowing a local user with access to the PAM responder's UNIX socket to send an empty or truncated PAM request. This malformed input triggers an out‑of‑bounds read, potentially causing the PAM responder to terminate or restart, which results in a local denial of service.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 6 through 10 and Red Hat OpenShift Container Platform 4. The affected component is the sssd PAM responder; no specific patch versions are listed, so any release within the stated families remains potentially vulnerable unless a patch has been applied.

Risk and Exploitability

With a CVSS score of 4.0, the vulnerability is considered moderate; the EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attack requires local access to the PAM responder socket (typically /var/lib/sss/pipes/pam), so only users or processes that can read or write to that socket can exploit it. Because it only causes a service crash, the impact is limited to denial of service, not data compromise.

Generated by OpenCVE AI on September 15, 2026 at 13:05 UTC.

Remediation

Vendor Workaround

There's no available mitigation for this issue.


OpenCVE Recommended Actions

  • Restrict the file permissions of the PAM responder UNIX socket (usually /var/lib/sss/pipes/pam) to trusted users, such as setting ownership to root and mode 0600.
  • If possible, rename or relocate the PAM responder socket to a location protected by SELinux or AppArmor, enforcing strict access controls.
  • Apply any Red Hat security updates for sssd that contain a fix, and monitor official advisories for later patches.

Generated by OpenCVE AI on September 15, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.
Title Sssd: sssd: denial of service via malformed pam v1 requests
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-125
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T14:47:35.665Z

Reserved: 2026-09-14T14:33:31.717Z

Link: CVE-2026-90994

cve-icon Vulnrichment

Updated: 2026-09-14T16:30:11.651Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T16:17:42.220

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-90994

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T14:36:00Z

Links: CVE-2026-90994 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses