---
id: CVE-2026-104045
title: A flaw was found in SSSD
summary: >-
  A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS)
  by exploiting a race condition in the autofs responder between asynchronous
  enumeration completion and map invalidation. By repeatedly sending concurrent
  map en…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-772
vendor: Red Hat
product: sssd
affected:
  - sssd (all versions)
  - sssd
  - sssd (all versions)
  - sssd (all versions)
  - sssd (all versions)
  - openshift/ose-rhel-coreos-8 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:04.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104045'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-104045'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2478663'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.978Z'
---

## Overview

A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. By repeatedly sending concurrent map enumeration and invalidation requests, an attacker can cause memory to leak, leading to excessive memory consumption that can disrupt or crash the autofs service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
