Red Hat SSSD是美国Red Hat公司的一款身份认证与权限管理软件。 Red Hat SSSD存在资源管理错误漏洞,该漏洞源于NSS responder的sss_nss_protocol_fill_initgr()函数为所有组条目预分配回复空间,但在跳过组时不收缩数据包,导致未初始化的堆字节被发送至客户端,本地攻击者可能利用此漏洞泄露缓存的目录数据和sssd_nss进程的堆布局信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42169 | 7.3 HIGH | Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c |
| CVE-2026-68743 | 5.5 MEDIUM | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v |
| CVE-2026-18103 | 4.9 MEDIUM | Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi |
| CVE-2026-17614 | 4.4 MEDIUM | Wildfly-core: path traversal on wildfly domain controller |
| CVE-2026-18569 | 3.7 LOW | Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logo |
No comments yet