CVE-2026-88252
Received Received - Intake

Denial of Service in SSSD via File Descriptor Exhaustion

Vulnerability report for CVE-2026-88252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat sssd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Denial of Service (DoS) flaw in sssd. A local attacker can exhaust the responder service's file descriptors by opening and maintaining many concurrent connections to a responder socket. This triggers an unthrottled retry loop, causing high CPU usage and stalling the service, which prevents legitimate identity and authentication requests from being processed.

Detection Guidance

Detecting this vulnerability involves monitoring for excessive file descriptor usage or high CPU utilization by the sssd responder service. Check for processes with unusually high file descriptor counts using commands like 'lsof -p <sssd_pid>' or 'ls /proc/<sssd_pid>/fd | wc -l'. Monitor CPU usage with 'top -p <sssd_pid>' or 'htop'. Look for stalled authentication requests or timeouts in logs like /var/log/sssd/*.log.

Impact Analysis

If exploited, this vulnerability can disrupt authentication and identity services on affected systems. Legitimate users may be unable to log in or access resources, leading to service outages or degraded performance. The impact is local, requiring attacker access to the system.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by exhausting system resources, which could disrupt authentication and identity management services. While it does not directly impact data confidentiality or integrity, prolonged service disruption may lead to unauthorized access attempts or delays in critical operations, potentially affecting compliance with standards requiring timely access controls or audit logging.

Mitigation Strategies

Monitor for high CPU usage or stalled responder service processes. Limit concurrent connections to sssd responder sockets and restrict local user access to prevent abuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart