CVE-2026-104035
Received Received - Intake

SSSD KCM Credential Manager Memory Exhaustion DoS

Vulnerability report for CVE-2026-104035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the System Security Services Daemon (SSSD) and specifically affects the Kerberos Credential Manager (KCM) responder. A local attacker can cause a denial of service by maintaining a persistent connection to the KCM UNIX socket and repeatedly storing and destroying credentials. This leads to unbounded memory growth because the service fails to release cached objects from memory when credentials are removed. The memory is only freed when the connection closes or the responder restarts.

Detection Guidance

Monitor memory usage of the sssd-kcm process using tools like top, htop, or ps. Look for persistent growth in memory consumption without corresponding credential operations. Check for unusual activity on the KCM UNIX socket at /var/lib/sss/pipes/sssd_kcm.

Impact Analysis

The impact is limited to availability loss for the KCM responder service. An attacker with local access could exhaust system memory, making the KCM responder unresponsive. This does not affect confidentiality or integrity of data but could disrupt services relying on Kerberos authentication managed by SSSD.

Compliance Impact

This vulnerability primarily impacts service availability and does not directly affect data confidentiality or integrity. Compliance with standards like GDPR or HIPAA depends on the specific use case, but since no data is exposed or altered, the main concern would be potential service disruption if the KCM responder becomes unresponsive.

Mitigation Strategies

Disable the KCM responder if not required by editing /etc/sssd/sssd.conf and setting kcm = false. Restrict access to the KCM socket by modifying filesystem permissions. Restart the sssd service after changes. Monitor memory usage and restart the KCM responder if abnormal growth is detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart