CVE-2026-104029
Received Received - Intake

Buffer Overflow in SSSD autofs Responder

Vulnerability report for CVE-2026-104029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: redhat-SADP

Description

A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104029 is a Denial of Service (DoS) vulnerability in SSSD affecting the autofs responder component. It involves an out-of-bounds memory read due to improper buffer offset calculation during request parsing. A local attacker can exploit this by sending a specially crafted request to the autofs responder UNIX socket, causing the process to crash.

Detection Guidance

Check if the autofs responder is running and the UNIX socket is accessible. Use commands like 'systemctl status sssd-autofs' to verify service status. Inspect logs for crashes in the autofs responder process using 'journalctl -u sssd-autofs --no-pager -n 50'.

Impact Analysis

The vulnerability can cause the autofs responder process to crash, resulting in a DoS. This disrupts services relying on autofs, such as automounting filesystems. Exploitation requires local access to the autofs UNIX socket and the responder must be enabled.

Compliance Impact

This vulnerability causes a denial of service (DoS) by crashing the autofs responder process, which may temporarily disrupt services but does not lead to data disclosure or system compromise. For compliance standards like GDPR or HIPAA, the primary concern would be service availability. A DoS could impact systems handling sensitive data, potentially violating availability requirements. However, since the vulnerability requires local access and does not expose data, the direct compliance impact is likely minimal unless critical services are affected.

Mitigation Strategies

Disable the autofs responder if not needed using 'systemctl disable --now sssd-autofs'. Restrict access to the autofs UNIX socket by modifying permissions or firewall rules. Monitor for crashes in the autofs responder process as a potential sign of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart