CVE-2026-104031
Received Received - Intake

Memory Exhaustion in SSSD Autofs Responder

Vulnerability report for CVE-2026-104031, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat sssd 2.12.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the System Security Services Daemon (SSSD) where memory allocated during autofs responder requests is not released until the client connection closes. A local attacker can exploit this by keeping a connection open and sending repeated valid requests, causing memory exhaustion and a Denial of Service (DoS).

Detection Guidance

Check if the autofs responder is running by running systemctl status sssd-autofs. If enabled, monitor memory usage of the sssd process with commands like ps aux | grep sssd or top. Look for repeated autofs requests in logs using journalctl -u sssd-autofs or tail -f /var/log/sssd/sssd_autofs.log.

Impact Analysis

The impact is primarily service disruption due to memory exhaustion in the autofs responder. It requires local access to an active autofs responder socket and repeated valid requests. The vulnerability does not affect system confidentiality or integrity, only availability of the responder service.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by exhausting memory in the SSSD autofs responder service. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged service unavailability could disrupt access to critical systems, potentially affecting compliance with availability requirements in these regulations.

Mitigation Strategies

Disable the autofs responder if not required using systemctl disable --now sssd-autofs. Restrict access to the autofs socket by ensuring only trusted local users can reach it. Monitor for unusual memory usage in sssd processes and apply patches when available from Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104031. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart