{"id":"CVE-2026-80048","title":"A flaw was found in `sssd-kcm`","summary":"A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the sy…","severity":"none","cwe":["CWE-770"],"vendor":"Red Hat","product":"sssd","affected":["sssd (all versions)","sssd","sssd (all versions)","sssd (all versions)","sssd (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T00:17:21.067","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80048","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-80048","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479377","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T00:26:32.093Z","slug":"CVE-2026-80048","body":"## Overview\n\nA flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the `sssd-kcm` responder, resulting in a Denial of Service (DoS) for affected deployments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}