Impact
A flaw was discovered in sssd whereby a local unprivileged user can send a specially crafted request with a zero‑length body to the NSS responder. The zero‑length request triggers a buffer handling error that causes the NSS responder to become unstable or terminate, resulting in a denial‑of‑service condition for system authentication services. The weakness corresponds to CWE‑191 (Integer Overflow or Division by Zero).
Affected Systems
This vulnerability is present in multiple Red Hat products, including Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat OpenShift Container Platform 4. All affected versions run the sssd service with the NSS responder enabled, unless it has been disabled by configuration.
Risk and Exploitability
The publicly available CVSS score is 4, indicating moderate severity. No EPSS information is available and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation has not been observed. Nevertheless, any local user who can reach the NSS responder socket may trigger the denial of service. The CNA recommends restricting or disabling the NSS responder socket to mitigate the issue.
OpenCVE Enrichment