{"id":"CVE-2026-104045","title":"A flaw was found in SSSD","summary":"A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. By repeatedly sending concurrent map en…","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-772"],"vendor":"Red Hat","product":"sssd","affected":["sssd (all versions)","sssd","sssd (all versions)","sssd (all versions)","sssd (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T21:17:04.163","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104045","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104045","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478663","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T21:20:28.978Z","slug":"CVE-2026-104045","body":"## Overview\n\nA flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. By repeatedly sending concurrent map enumeration and invalidation requests, an attacker can cause memory to leak, leading to excessive memory consumption that can disrupt or crash the autofs service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}