Impact
SSSD contains a null pointer dereference in its PAM responder that can be triggered by a specially crafted request when the pam_app_services option is enabled. An attacker with local privileges sufficient to connect to the PAM responder socket can omit a service entry from the request, causing a crash. The crash results in a denial of service against authentication and authorization functions, potentially affecting all users on the system but not compromising confidentiality or integrity.
Affected Systems
The issue affects all Red Hat Enterprise Linux releases 6 through 9 and Red Hat OpenShift Container Platform 4, as well as the 10th RHEL family. Any system running SSSD with the pam_app_services parameter set in /etc/sssd/sssd.conf is vulnerable. No specific patch versions are listed, so all currently supported releases that still use this configuration are impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact, and the EPSS score is not available. Because the vulnerability can only be triggered by a local attacker with sufficient privileges to communicate with the PAM socket, it is unlikely to be exploited remotely. The lack of a KEV listing and the absence of publicly documented exploits reduce the likelihood of large‑scale attacks, but the denial of service can still cause significant disruption to authentication services on the affected hosts.
OpenCVE Enrichment