CVE-2026-68742
Received Received - Intake

Out-of-Bounds Read in SSSD NSS Responder

Vulnerability report for CVE-2026-68742, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: Red Hat, Inc.

Description

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat sssd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in SSSD's NSS responder. The sss_nss_protocol_parse_addr() function fails to validate the addrlen field against the packet size. A local attacker can send a crafted GETHOSTBYADDR request to trigger an out-of-bounds read, crashing the process and causing a denial of service.

Detection Guidance

This vulnerability can be detected by monitoring for crashes in the SSSD NSS responder process or examining logs for malformed GETHOSTBYADDR requests. Check SSSD logs for segmentation faults or out-of-bounds read errors in the NSS responder component.

Impact Analysis

If exploited, this flaw could allow a local attacker to crash the SSSD service on your system, leading to service disruption and potential loss of access to authentication and identity services.

Mitigation Strategies

Update SSSD to the latest patched version. Restrict local access to the NSS responder socket to prevent unauthorized requests. Monitor for suspicious activity targeting the NSS responder.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart