CVE-2026-104042Medium· 5.5▾ SunlitA flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing the token, causing the PAM responder to crash.
sssd (all versions)sssdsssd (all versions)sssd (all versions)sssd (all versions)openshift/ose-rhel-coreos-8 (all versions)openshift/ose-rhel-coreos-9 (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104043Medium· 5.5Sssd: sssd: denial of service via undersized packet parsing in nss responder
CVE-2026-104037Medium· 5.5A flaw was found in SSSD
CVE-2026-104030Medium· 5.5A flaw was found in sssd
CVE-2026-104029Low· 3.3A flaw was found in SSSD
CVE-2026-90994Medium· 4.0A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()
CVE-2026-90463Medium· 4.0A flaw was found in the sssd NSS responder