Impact
A flaw was discovered in the PAM responder's protocol v1 parser in sssd, allowing a local user with access to the PAM responder's UNIX socket to send an empty or truncated PAM request. This malformed input triggers an out‑of‑bounds read, potentially causing the PAM responder to terminate or restart, which results in a local denial of service.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 6 through 10 and Red Hat OpenShift Container Platform 4. The affected component is the sssd PAM responder; no specific patch versions are listed, so any release within the stated families remains potentially vulnerable unless a patch has been applied.
Risk and Exploitability
With a CVSS score of 4.0, the vulnerability is considered moderate; the EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attack requires local access to the PAM responder socket (typically /var/lib/sss/pipes/pam), so only users or processes that can read or write to that socket can exploit it. Because it only causes a service crash, the impact is limited to denial of service, not data compromise.
OpenCVE Enrichment