CVE-2026-104044
Received Received - Intake

Denial of Service in SSSD via Uninitialized Pointer Dereference

Vulnerability report for CVE-2026-104044, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This failure disrupts authentication services on the host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL pointer dereference vulnerability in sssd where a local attacker can crash the PAM responder by sending a specially crafted passkey Kerberos authentication request. The flaw occurs when the passkey pre-authentication state is not initialized but the code attempts to access it, causing a denial of service.

Detection Guidance

To detect this vulnerability, check if sssd is running with passkey authentication enabled. Look for crashes in the sssd_pam service or logs indicating NULL pointer dereferences in passkey Kerberos handling. Monitor PAM responder socket access attempts.

Impact Analysis

An attacker with local access could crash the sssd_pam service, disrupting authentication on the host. This would prevent users from logging in or authenticating until the service is restarted. The impact is limited to availability and requires local access.

Compliance Impact

This vulnerability causes a local Denial of Service (DoS) by crashing the sssd_pam service, disrupting authentication services. It does not directly impact confidentiality or integrity but may affect availability of authentication systems. Compliance impact depends on system criticality and redundancy measures.

Mitigation Strategies

Disable pam_passkey_auth if passkey authentication is not required. Restrict access to the PAM responder socket to trusted users only. Monitor for crashes in sssd_pam and apply any future official patches from Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104044. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart