CVE-2026-104037
Received Received - Intake

Integer Underflow in SSSD Autofs Responder Leads to DoS

Vulnerability report for CVE-2026-104037, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Denial of Service (DoS) vulnerability in SSSD's autofs responder component. A local attacker can send a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, crashing the responder process and disrupting service.

Detection Guidance

Check if the autofs responder is enabled in SSSD configuration by inspecting /etc/sssd/sssd.conf for the autofs responder section. Verify if the UNIX socket for autofs responder exists at /var/lib/sss/pipes/nss or similar path. Monitor logs for autofs responder crashes or errors in /var/log/sssd/.

Impact Analysis

The vulnerability can crash the autofs responder process, leading to a temporary loss of service for automount functionality. It requires local access and a configured autofs responder socket to exploit. No privilege escalation or data loss occurs, but availability is affected.

Compliance Impact

This vulnerability causes a denial of service (DoS) by crashing the SSSD autofs responder process through a local attack. It does not lead to data breaches, privilege escalation, or unauthorized access, which are primary concerns for GDPR and HIPAA compliance. The impact is limited to service availability disruption.

Mitigation Strategies

Disable the autofs responder in SSSD configuration if not needed by setting autofs_provider to none in /etc/sssd/sssd.conf and restarting SSSD. Restrict access to the autofs responder UNIX socket by adjusting file permissions or using firewall rules. Apply available patches from Red Hat or your distribution vendor as soon as they are released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104037. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart