CVE-2026-104036
Received Received - Intake

SSSD NFS idmap plugin out-of-bounds write vulnerability

Vulnerability report for CVE-2026-104036, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized cached entries, resulting in an out-of-bounds write. This flaw primarily leads to a Denial of Service (DoS) by crashing the identity mapping service, and may also corrupt adjacent process memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write flaw in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin checks if an entry exceeds the buffer size but fails to stop before copying data. This leads to memory corruption. A local attacker can trigger this by requesting identity lookups that resolve to oversized cached entries, causing a Denial of Service (DoS) or potential memory corruption.

Detection Guidance

Check if SSSD's NFS idmap plugin is in use by verifying the configuration of rpc.idmapd. Look for 'Method = sss' and memcache enabled in SSSD configuration files. Monitor for crashes in the idmap process or unusual memory corruption errors in system logs.

Impact Analysis

This vulnerability primarily causes a Denial of Service (DoS) by crashing the identity mapping service. It may also corrupt adjacent process memory. Exploitation requires specific conditions like using the SSSD NFS plugin with memcached lookups enabled and rpc.idmapd configured with Method = sss. A local attacker could destabilize the service but unlikely to gain remote access or escalate privileges in default setups.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by crashing the identity mapping service, which could disrupt access to user or group information. While it may corrupt adjacent memory, there is no evidence of reliable privilege escalation or remote exploitation. Compliance impacts would depend on whether the affected service is critical for data access or processing in regulated environments like GDPR or HIPAA. A DoS could temporarily prevent authorized users from accessing systems, potentially violating availability requirements in these standards.

Mitigation Strategies

Disable the memcache path by setting 'memcache = false' in the SSSD rpc.idmapd plugin configuration. Alternatively, avoid using 'Method = sss' for rpc.idmapd until a patch is available. Restart the SSSD service after making changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104036. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart