SSSD 中发现了一个漏洞。当 SSSD 配置为在 LDAP(轻量级目录访问协议)环境中,于评估限制性访问规则之前先检查密码过期警告时,密码过期警告会提前终止规则评估,并将该访问请求视为成功。拥有已过期密码但使用替代认证方法(例如 SSH 公钥认证)的远程认证用户可利用此漏洞,绕过访问控制限制,从而获得对受保护系统的未授权访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104044 | 6.2 MEDIUM | Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
| CVE-2026-104038 | 5.9 MEDIUM | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-104036 | 5.8 MEDIUM | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104043 | 5.5 MEDIUM | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-104042 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104041 | 5.5 MEDIUM | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104037 | 5.5 MEDIUM | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104035 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104032 | 5.5 MEDIUM | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104031 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-105305 | 5.4 MEDIUM | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim |
| CVE-2026-104033 | 5.4 MEDIUM | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-104039 | 4.7 MEDIUM | Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder |
| CVE-2026-104034 | 4.7 MEDIUM | Sssd: sssd: denial of service via use-after-free in kcm ticket renewal |
| CVE-2026-104040 | 4.4 MEDIUM | Sssd: sssd: information disclosure via odata injection in entra id lookups |
No comments yet