CVE-2026-104038
Received Received - Intake

Denial of Service in SSSD via Missing SID Extension

Vulnerability report for CVE-2026-104038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service (DoS) vulnerability in sssd where a remote attacker can crash the service by submitting a certificate missing a required Security Identifier (SID) extension. The flaw occurs in deployments using SID-based certificate mapping rules, as sssd fails to verify the SID extension before processing the certificate, leading to a crash during authentication or lookup operations.

Detection Guidance

Check SSSD logs for crashes during certificate authentication or lookup operations. Look for entries indicating NULL pointer dereferences in expand_sid() or missing SID extensions in certificates. Use journalctl -u sssd to review logs for process terminations related to certificate processing.

Impact Analysis

The impact is limited to certificate-driven authentication and lookup flows. If exploited, it can cause the SSSD process to crash, disrupting authentication services and potentially leading to service unavailability. Exploitation requires a vulnerable configuration with LDAPU1 mapping rules using SID or RID templates and a specially crafted certificate.

Compliance Impact

This vulnerability primarily causes a denial of service by crashing SSSD during certificate processing, which could disrupt authentication and lookup operations in affected systems. It does not directly expose or leak data, but prolonged downtime may impact availability of services handling sensitive information. Compliance impact depends on the affected system's role in processing regulated data (e.g., patient records for HIPAA or personal data for GDPR). Downtime could lead to violations if critical services become unavailable.

Mitigation Strategies

Disable LDAPU1 certificate mapping rules that expand {sid} or {sid.rid} until a patch is available. Configure your system to reject certificates lacking the SID extension OID 1.3.6.1.4.1.311.25.2 before they reach SSSD. Monitor for SSSD crashes and update to a patched version once released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart