发现 SSSD 中存在一个安全漏洞。当配置为使用 Microsoft Entra ID 时,搜索输入在嵌入目录查询过滤器之前未进行适当的清理。本地用户可通过提交构造的查找请求来利用此漏洞,操纵查询逻辑,从而导致目录中的未授权信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106062 | 7.8 HIGH | Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file |
| CVE-2026-101258 | 7.8 HIGH | Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedur |
| CVE-2026-83550 | 7.1 HIGH | Postgres-exporter: net/http/pprof exposed on metrics listener |
| CVE-2026-104048 | 6.8 MEDIUM | Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation |
| CVE-2026-92821 | 6.8 MEDIUM | Sssd: sssd: access control bypass via premature ldap access rule evaluation |
| CVE-2026-106063 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions |
| CVE-2026-104046 | 6.2 MEDIUM | Sssd: sssd: denial of service via incomplete identity provider authentication requests |
| CVE-2026-104044 | 6.2 MEDIUM | Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
| CVE-2026-104038 | 5.9 MEDIUM | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-104036 | 5.8 MEDIUM | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104031 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-104032 | 5.5 MEDIUM | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104035 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104037 | 5.5 MEDIUM | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104041 | 5.5 MEDIUM | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104042 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104043 | 5.5 MEDIUM | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-105305 | 5.4 MEDIUM | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim |
| CVE-2026-104033 | 5.4 MEDIUM | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-106033 | 5.4 MEDIUM | Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet