发现 SSSD(System Security Services Daemon)中存在一个安全漏洞。当 SSSD 配置为使用 Entra ID 身份提供程序时,包含单引号的输入查找名称在被嵌入 Microsoft Graph Open Data Protocol (OData) 查询之前未被正确转义。低权限本地用户可通过提交构造的搜索请求,篡改查询过滤器,从而扩大用户或组搜索范围。此漏洞可能导致敏感信息泄露,因为攻击者可以检索到非预期的目录对象;同时,还可能因过度的资源消耗和缓存填充而导致服务拒绝(Denial o
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92821 | 6.8 MEDIUM | Sssd: sssd: access control bypass via premature ldap access rule evaluation |
| CVE-2026-104044 | 6.2 MEDIUM | Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
| CVE-2026-104038 | 5.9 MEDIUM | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-104036 | 5.8 MEDIUM | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104043 | 5.5 MEDIUM | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-104042 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104041 | 5.5 MEDIUM | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104037 | 5.5 MEDIUM | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104035 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104032 | 5.5 MEDIUM | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104031 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-105305 | 5.4 MEDIUM | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim |
| CVE-2026-104033 | 5.4 MEDIUM | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-104039 | 4.7 MEDIUM | Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder |
| CVE-2026-104034 | 4.7 MEDIUM | Sssd: sssd: denial of service via use-after-free in kcm ticket renewal |
No comments yet