CVE-2026-90462
- EPSS 0.21%
- Veröffentlicht 22.09.2026 15:50:00
- Zuletzt bearbeitet 07.10.2026 13:41:47
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorre...
CVE-2026-90996
- EPSS 0.11%
- Veröffentlicht 14.09.2026 15:55:42
- Zuletzt bearbeitet 07.10.2026 14:29:19
A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become...
CVE-2026-68743
- EPSS 0.13%
- Veröffentlicht 04.08.2026 18:37:21
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to...
CVE-2026-68744
- EPSS 0.09%
- Veröffentlicht 04.08.2026 05:28:30
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to t...
CVE-2026-68742
- EPSS 0.13%
- Veröffentlicht 03.08.2026 10:16:33
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS res...
CVE-2026-12610
- EPSS 0.12%
- Veröffentlicht 30.06.2026 08:27:01
- Zuletzt bearbeitet 31.08.2026 19:16:45
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or...
CVE-2026-6245
- EPSS 0.14%
- Veröffentlicht 15.04.2026 18:35:19
- Zuletzt bearbeitet 01.09.2026 12:17:43
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C str...
CVE-2023-3758
- EPSS 1.03%
- Veröffentlicht 18.04.2024 19:15:08
- Zuletzt bearbeitet 03.11.2025 21:15:59
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
CVE-2022-4254
- EPSS 0.95%
- Veröffentlicht 01.02.2023 17:15:09
- Zuletzt bearbeitet 27.03.2025 15:15:41
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
CVE-2021-3621
- EPSS 2.52%
- Veröffentlicht 23.12.2021 21:15:08
- Zuletzt bearbeitet 03.11.2025 21:15:42
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as...