发现 SSSD 存在一个漏洞。本地用户可通过干扰系统身份验证服务,导致拒绝服务(DoS)。在处理 Pluggable Authentication Module (PAM) 响应程序中的通用安全服务应用程序编程接口(GSSAPI)身份验证时,完成操作后缓存的连接状态会被释放,但引用指针未被清零。攻击者可通过在同一连接上发送额外请求进行利用,导致服务访问无效内存并意外终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92821 | 6.8 MEDIUM | Sssd: sssd: access control bypass via premature ldap access rule evaluation |
| CVE-2026-104044 | 6.2 MEDIUM | Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
| CVE-2026-104038 | 5.9 MEDIUM | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-104036 | 5.8 MEDIUM | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104043 | 5.5 MEDIUM | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-104042 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104041 | 5.5 MEDIUM | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104037 | 5.5 MEDIUM | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104035 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104032 | 5.5 MEDIUM | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104031 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-105305 | 5.4 MEDIUM | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim |
| CVE-2026-104033 | 5.4 MEDIUM | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-104034 | 4.7 MEDIUM | Sssd: sssd: denial of service via use-after-free in kcm ticket renewal |
| CVE-2026-104040 | 4.4 MEDIUM | Sssd: sssd: information disclosure via odata injection in entra id lookups |
No comments yet