在 sssd 的 NSS 响应器中发现了一个缺陷。这是一个输入验证漏洞,允许本地攻击者通过向 NSS 响应器的 UNIX 套接字发送精心构造的服务查找请求,从而引发越界读取。该越界读取可能导致 NSS 响应器进程崩溃,进而造成服务拒绝(DoS)。虽然非特权本地客户端通常能够访问该套接字,但目前没有证据表明存在权限提升或可靠的数据泄露风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90947 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file |
| CVE-2026-90949 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis |
| CVE-2026-90948 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png |
| CVE-2026-90995 | 5.5 MEDIUM | Sssd: sssd: local denial of service due to null pointer dereference in pam responder |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90994 | 4.0 MEDIUM | Sssd: sssd: denial of service via malformed pam v1 requests |
No comments yet