Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90995— Sssd: sssd: local denial of service due to null pointer dereference in pam responder

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 SSSD(系统安全服务守护进程)中发现了一个缺陷。具有连接权限至 PAM(可插拔认证模块)响应套接字的本地攻击者可以发送一个特制的协议请求。如果启用了 配置,且请求中省略了服务项,则可能发生空指针引用。该漏洞会导致服务中断,使 PAM 响应进程崩溃,从而中断认证服务。

CVSS 5.5 · Medium

Possible ATT&CK Techniques 1 AI

T1069 · Permission Groups Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90995

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sssd: sssd: local denial of service due to null pointer dereference in pam responder
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-90995

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90995

登录查看更多情报信息。

Vendor Advisories for CVE-2026-90995 (1)

Other References for CVE-2026-90995 (1)

Same Patch Batch · Red Hat · 2026-09-14 · 7 CVEs total

CVE-2026-90947 7.8 HIGH Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file
CVE-2026-90949 7.8 HIGH Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis
CVE-2026-90948 7.8 HIGH Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png
CVE-2026-90996 4.0 MEDIUM Sssd: sssd: denial of service in nss responder via crafted zero-length requests
CVE-2026-90994 4.0 MEDIUM Sssd: sssd: denial of service via malformed pam v1 requests
CVE-2026-90463 4.0 MEDIUM Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `

IV. Related Vulnerabilities

V. Comments for CVE-2026-90995

No comments yet


Leave a comment