Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90463— Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 sssd 的 NSS 响应器中发现了一个缺陷。这是一个输入验证漏洞,允许本地攻击者通过向 NSS 响应器的 UNIX 套接字发送精心构造的服务查找请求,从而引发越界读取。该越界读取可能导致 NSS 响应器进程崩溃,进而造成服务拒绝(DoS)。虽然非特权本地客户端通常能够访问该套接字,但目前没有证据表明存在权限提升或可靠的数据泄露风险。

CVSS 4.0 · Medium

Possible ATT&CK Techniques 1 AI

T1012 · Query Registry
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90463

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-90463

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90463

登录查看更多情报信息。

Vendor Advisories for CVE-2026-90463 (1)

Other References for CVE-2026-90463 (1)

Same Patch Batch · Red Hat · 2026-09-14 · 7 CVEs total

CVE-2026-90947 7.8 HIGH Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file
CVE-2026-90949 7.8 HIGH Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis
CVE-2026-90948 7.8 HIGH Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png
CVE-2026-90995 5.5 MEDIUM Sssd: sssd: local denial of service due to null pointer dereference in pam responder
CVE-2026-90996 4.0 MEDIUM Sssd: sssd: denial of service in nss responder via crafted zero-length requests
CVE-2026-90994 4.0 MEDIUM Sssd: sssd: denial of service via malformed pam v1 requests

IV. Related Vulnerabilities

V. Comments for CVE-2026-90463

No comments yet


Leave a comment