Fedoraproject

Sssd

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 04.08.2026 18:37:21
  • Zuletzt bearbeitet 17.08.2026 13:10:02

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to...

  • EPSS 0.09%
  • Veröffentlicht 04.08.2026 05:28:30
  • Zuletzt bearbeitet 18.08.2026 16:37:05

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to t...

  • EPSS 0.13%
  • Veröffentlicht 03.08.2026 10:16:33
  • Zuletzt bearbeitet 18.08.2026 16:36:32

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS res...

  • EPSS 0.12%
  • Veröffentlicht 30.06.2026 08:27:01
  • Zuletzt bearbeitet 30.06.2026 20:08:54

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or...

  • EPSS 0.14%
  • Veröffentlicht 15.04.2026 18:35:19
  • Zuletzt bearbeitet 12.08.2026 16:24:06

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C str...

Exploit
  • EPSS 1.03%
  • Veröffentlicht 18.04.2024 19:15:08
  • Zuletzt bearbeitet 03.11.2025 21:15:59

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

Exploit
  • EPSS 0.95%
  • Veröffentlicht 01.02.2023 17:15:09
  • Zuletzt bearbeitet 27.03.2025 15:15:41

sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters

  • EPSS 2.52%
  • Veröffentlicht 23.12.2021 21:15:08
  • Zuletzt bearbeitet 03.11.2025 21:15:42

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as...

Exploit
  • EPSS 1.61%
  • Veröffentlicht 26.12.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 01:40:55

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • EPSS 1.1%
  • Veröffentlicht 25.03.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:24

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.