CVE-2026-68744
Analyzed Analyzed - Analysis Complete

SSSD NSS Responder Heap Information Disclosure

Vulnerability report for CVE-2026-68744, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-18

Assigner: redhat-SADP

Description

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-18
Generated
2026-08-24
AI Q&A
2026-08-04
EPSS Evaluated
2026-08-23
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
redhat enterprise_linux 7.0
fedoraproject sssd *
redhat enterprise_linux 8.0
redhat openshift_container_platform 4.0
redhat enterprise_linux 9.0
redhat enterprise_linux 10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in SSSD where the sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped. This causes uninitialized heap bytes to be transmitted to the client, potentially exposing cached directory data and heap layout information.

Detection Guidance

This vulnerability involves uninitialized heap bytes in SSSD's NSS responder. Detection requires checking SSSD logs for memory-related errors or unusual packet sizes in NSS responses. Monitor sssd_nss process memory usage and inspect network traffic for malformed NSS protocol packets. No specific commands are provided in the context.

Impact Analysis

A local attacker could exploit this to disclose sensitive cached directory data and heap layout information from the sssd_nss process, which may lead to further attacks or information leakage.

Compliance Impact

This vulnerability may lead to disclosure of cached directory data and heap layout information, which could expose sensitive user information. This could potentially violate compliance requirements under GDPR and HIPAA by compromising data confidentiality.

Mitigation Strategies

Update SSSD to the latest patched version to address the heap memory leak issue. Monitor system logs for unusual activity in the sssd_nss process. Restrict local access to prevent unauthorized exploitation of cached directory data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68744. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart