VulnSea

sssd vulnerabilities

CVEs whose affected-version data names the sssd package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-90996Medium· 4.0
1w ago

A flaw was found in sssd

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…

SunlitRed Hat · sssdEPSS 0.11%via NVD
CVE-2026-90995Medium· 5.5
1w ago

A flaw was found in SSSD (System Security Services Daemon)

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_service…

SunlitRed Hat · sssdEPSS 0.11%via NVD
CVE-2026-90994Medium· 4.0
1w ago

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…

SunlitRed Hat · sssdEPSS 0.12%via NVD
CVE-2026-90463Medium· 4.0
1w ago

A flaw was found in the sssd NSS responder

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…

SunlitRed Hat · sssdEPSS 0.10%via NVD
CVE-2026-87853High· 7.5
1w ago

A flaw was found in SSSD's IdP authentication provider

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …

TwilightRed Hat · sssdEPSS 0.28%via NVD
CVE-2026-6245Medium· 5.5
5mo ago

A flaw was found in the System Security Services Daemon (SSSD)

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-ter…

Sunlitfedoraproject · sssdEPSS 0.14%via NVD
sssd vulnerabilities (CVEs) · VulnSea