CVE-2026-104042
Received Received - Intake

Denial of Service in SSSD via PAM Request

Vulnerability report for CVE-2026-104042, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing the token, causing the PAM responder to crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Denial of Service (DoS) vulnerability in the System Security Services Daemon (SSSD) affecting the PAM responder component. It occurs when a local attacker sends a crafted PAM request with a zero-length authentication token to the responder socket. Due to missing input validation, the service crashes while processing the token because it attempts to read beyond buffer boundaries.

Detection Guidance

Monitor the SSSD PAM responder service for crashes or unexpected terminations. Check logs for segmentation faults or errors related to the PAM responder component. Use commands like 'journalctl -u sssd-pam' or 'systemctl status sssd-pam' to inspect service status and logs for anomalies.

Impact Analysis

The vulnerability can disrupt the availability of the PAM responder service for local clients. While it does not allow privilege escalation or unauthorized data access, it can cause system crashes when exploited, leading to service interruptions for authentication requests.

Compliance Impact

This vulnerability primarily impacts service availability and could lead to disruptions in authentication systems. While it does not directly cause data breaches, prolonged DoS conditions might affect compliance with availability requirements in standards like GDPR or HIPAA, which mandate reliable access to systems handling personal or health data.

Mitigation Strategies

Restrict access to the PAM responder socket to trusted users only. Temporarily disable the SSSD PAM responder service if possible, or apply vendor patches if available. Monitor for any signs of exploitation attempts or service disruptions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104042. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart