sssd 中存在一个缺陷,具体位于 PAM(可插拔认证模块)响应器的协议 v1 解析器 中。拥有 PAM 响应器 UNIX 套接字访问权限的本地客户端,可以通过协商使用协议 v1 并发送一个为空或被截断的 PAM 请求体来利用此缺陷。这可能触发越界读取,导致 PAM 响应器终止或重启,从而引发本地拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90947 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file |
| CVE-2026-90949 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis |
| CVE-2026-90948 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png |
| CVE-2026-90995 | 5.5 MEDIUM | Sssd: sssd: local denial of service due to null pointer dereference in pam responder |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90463 | 4.0 MEDIUM | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / ` |
No comments yet