在 SSSD(System Security Services Daemon)中发现了一个漏洞。本地攻击者可以通过向 autofs 响应程序(autofs responder)的 UNIX 套接字发送特制请求来利用此漏洞。由于在请求解析过程中存在不当的缓冲区偏移量计算,服务会执行越界内存读取操作。此漏洞可能导致 autofs 响应进程崩溃,从而引发拒绝服务(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101919 | 8.8 HIGH | Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to contro |
| CVE-2026-71299 | 6.5 MEDIUM | Maestro: maestro: rest api write endpoints registered without authentication middleware |
| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-71298 | 6.4 MEDIUM | Maestro: sql identifier injection via properties.* search filter and orderby field |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-104030 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-71297 | 5.4 MEDIUM | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional |
| CVE-2026-102295 | 5.4 MEDIUM | Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter |
| CVE-2026-102576 | 4.2 MEDIUM | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
| CVE-2026-105326 | 2.5 LOW | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
No comments yet