CVE-2026-104043
Received Received - Intake

Integer Underflow in SSSD NSS Responder Leads to DoS

Vulnerability report for CVE-2026-104043, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process and resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in SSSD, a service managing identity and authentication. A local attacker with access to the NSS responder UNIX socket can send a specially crafted packet with an undersized header. This triggers an integer underflow, causing an out-of-bounds memory read during packet parsing. The result is a crash of the responder process, leading to a Denial of Service (DoS).

Detection Guidance

To detect this vulnerability, monitor for crashes in the SSSD NSS responder process. Check logs for segmentation faults or unexpected terminations in sssd_nss. Examine network traffic for unusually small packets sent to the NSS responder UNIX socket at /var/lib/sss/pipes/nss. Use tools like strace to trace system calls made by local processes interacting with the socket.

Impact Analysis

The impact is limited to local users with socket access. It disrupts identity and group resolution services, causing crashes in the NSS responder. This leads to temporary unavailability of user authentication and lookup functions on the affected system.

Compliance Impact

This vulnerability primarily affects system availability. It does not lead to data disclosure or privilege escalation, so it likely has minimal direct impact on compliance with GDPR or HIPAA. However, prolonged DoS conditions could disrupt access to critical services, potentially affecting operational compliance.

Mitigation Strategies

Restrict access to the NSS responder UNIX socket at /var/lib/sss/pipes/nss to trusted local users only. Apply socket ACLs or peer-UID restrictions to limit which processes can connect. Monitor for suspicious activity involving the socket. Consider disabling the NSS responder if not required. Apply vendor patches if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104043. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart