CVE-2026-104034
Received Received - Intake

SSSD KCM Responder Use-After-Free in Kerberos Ticket Renewal

Vulnerability report for CVE-2026-104034, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-825 The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in SSSD's Kerberos Credential Manager (KCM) responder. It occurs during Kerberos ticket renewal when a deferred callback tries to access memory that was already freed. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems with KCM renewal enabled, causing the KCM responder service to crash and resulting in a Denial of Service (DoS).

Detection Guidance

Check if SSSD KCM responder is running with 'systemctl status sssd-kcm'. Look for crashes or instability in the KCM service logs. Verify if 'tgt_renewal = true' is set in SSSD configuration files like /etc/sssd/sssd.conf. Monitor for unexpected terminations of the KCM responder process.

Impact Analysis

This vulnerability can cause the KCM responder service to crash, leading to a localized denial of service. It requires an authenticated local user with a renewable Kerberos ticket and specific non-default configurations. Standard deployments are not affected as KCM renewal is disabled by default.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by crashing the KCM responder service, which does not directly expose sensitive credential data or allow privilege escalation. It requires local authenticated access and non-default configurations, reducing the risk of compliance violations. However, prolonged service disruption could impact availability of systems handling regulated data, potentially affecting compliance with availability requirements in standards like GDPR or HIPAA.

Mitigation Strategies

Disable the 'tgt_renewal' feature in SSSD configuration if not required. Update SSSD to a patched version once available. Restart the SSSD service after making changes. Ensure KCM renewal is not enabled in non-default configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104034. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart