---
id: CVE-2026-104035
title: A flaw was found in SSSD
summary: >-
  A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM)
  responder allows a local user to cause a Denial of Service (DoS) by
  maintaining a persistent connection and repeatedly storing and destroying
  credentials. Becaus…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-772
vendor: Red Hat
product: sssd
affected:
  - sssd (all versions)
  - sssd
  - sssd (all versions)
  - sssd (all versions)
  - sssd (all versions)
  - openshift/ose-rhel-coreos-8 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T01:16:34.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104035'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-104035'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2479107'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T00:37:36.246Z'
---

## Overview

A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
