CVE-2026-104041
Received Received - Intake

SSSD NSS Responder Memory Exhaustion DoS

Vulnerability report for CVE-2026-104041, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS) responder. Because the negative cache does not limit the total number of stored entries and only removes expired records when an existing key is rechecked, the cache can grow without bound. This behavior can lead to memory exhaustion, resulting in a Denial of Service (DoS) as the responder becomes unresponsive or terminates.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the System Security Services Daemon (sssd). An unprivileged local user can cause a Denial of Service (DoS) by repeatedly requesting lookups for nonexistent entries through the Name Service Switch (NSS) responder. The negative cache in sssd does not limit the number of stored entries and only removes expired records when a key is rechecked, allowing the cache to grow without bound. This can exhaust memory, making the responder unresponsive or causing it to terminate.

Detection Guidance

To detect this vulnerability, monitor sssd memory usage and negative cache growth. Check if the sssd_nss responder is active and accessible to local users. Use commands like 'ss -lpn | grep sssd' to verify socket access and 'systemctl status sssd-nss' to check responder status. High memory consumption by sssd_nss may indicate exploitation.

Impact Analysis

If exploited, this vulnerability can lead to memory exhaustion on the affected system, causing the sssd NSS responder to become unresponsive or crash. This disrupts local name-service availability, potentially affecting user logins, authentication, and other services relying on sssd for identity resolution. The attack requires local access and cannot be triggered remotely in standard configurations.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by exhausting memory through unbounded negative cache growth in SSSD. It does not directly lead to data disclosure or privilege escalation, which are key concerns for GDPR and HIPAA compliance. However, a DoS condition could disrupt system availability, potentially violating availability requirements in these regulations if critical services depend on SSSD for identity resolution.

Mitigation Strategies

Set 'entry_negative_timeout=0' in sssd.conf to disable non-permanent negative cache entries. Restrict untrusted local user access to the sssd responder socket. Upgrade sssd to a patched version if available. Monitor system memory usage for sssd_nss to detect abnormal growth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104041. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart