在 SSSD(系统安全服务守护进程)中发现了一个缺陷。具有连接权限至 PAM(可插拔认证模块)响应套接字的本地攻击者可以发送一个特制的协议请求。如果启用了 配置,且请求中省略了服务项,则可能发生空指针引用。该漏洞会导致服务中断,使 PAM 响应进程崩溃,从而中断认证服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90947 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file |
| CVE-2026-90949 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis |
| CVE-2026-90948 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90994 | 4.0 MEDIUM | Sssd: sssd: denial of service via malformed pam v1 requests |
| CVE-2026-90463 | 4.0 MEDIUM | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / ` |
No comments yet