Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-80048— Sssd: sssd-kcm: local denial of service via excessive memory preallocation

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 中发现了一个漏洞。能够连接到 UNIX 套接字的本地用户或进程可以利用此漏洞。攻击者通过发送一个较大的请求长度头,然后挂起连接,可以导致系统预分配大量内存。这会导致 响应程序中的内存耗尽,从而对受影响的服务部署造成拒绝服务(DoS)攻击。

AI Predicted 5.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80048

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sssd: sssd-kcm: local denial of service via excessive memory preallocation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the `sssd-kcm` responder, resulting in a Denial of Service (DoS) for affected deployments.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-80048

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80048

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-80048 (2)

Same Patch Batch · Red Hat · 2026-10-06 · 27 CVEs total

CVE-2026-106062 7.8 HIGH Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file
CVE-2026-101258 7.8 HIGH Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedur
CVE-2026-83550 7.1 HIGH Postgres-exporter: net/http/pprof exposed on metrics listener
CVE-2026-104048 6.8 MEDIUM Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
CVE-2026-92821 6.8 MEDIUM Sssd: sssd: access control bypass via premature ldap access rule evaluation
CVE-2026-106063 6.3 MEDIUM Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
CVE-2026-104046 6.2 MEDIUM Sssd: sssd: denial of service via incomplete identity provider authentication requests
CVE-2026-104044 6.2 MEDIUM Sssd: sssd: denial of service via crafted passkey kerberos authentication request
CVE-2026-104038 5.9 MEDIUM Sssd: sssd: denial of service via missing sid extension in certificate mapping
CVE-2026-104036 5.8 MEDIUM Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin
CVE-2026-104031 5.5 MEDIUM Sssd: sssd: denial of service via memory exhaustion in autofs responder
CVE-2026-104032 5.5 MEDIUM Sssd: sssd: denial of service via unprivileged autofs cache invalidation
CVE-2026-104035 5.5 MEDIUM Sssd: sssd: denial of service via memory exhaustion in kcm responder
CVE-2026-104037 5.5 MEDIUM Sssd: sssd: denial of service via packet length underflow in autofs responder
CVE-2026-104041 5.5 MEDIUM Sssd: sssd: denial of service via unbounded negative cache growth
CVE-2026-104042 5.5 MEDIUM Sssd: sssd: denial of service via out-of-bounds read in pam responder
CVE-2026-104043 5.5 MEDIUM Sssd: sssd: denial of service via undersized packet parsing in nss responder
CVE-2026-105305 5.4 MEDIUM Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim
CVE-2026-106033 5.4 MEDIUM Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter
CVE-2026-104033 5.4 MEDIUM Sssd: sssd: access control bypass via improper ldap shadow expiration check

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80048

No comments yet


Leave a comment