Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12610

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sssdunfixedpackage
sssdno-dsatrixiepackage
sssdpostponedbookwormpackage
sssdpostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2490288

  • https://github.com/SSSD/sssd/issues/8796

  • https://github.com/SSSD/sssd/commit/fa7a55949a30fed064a28ea6f0c801fc5e8c5ba7 (master)

  • https://github.com/SSSD/sssd/commit/f2c69b916f5fe53a930aa39c2078b248b83bc2b4 (sssd-2-13 branch)

  • https://github.com/SSSD/sssd/commit/db7ffa3ea6a971bb84bc54558ca7217751724334 (sssd-2-9 branch)

EPSS

Процентиль: 2%
0.00121
Низкий

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 2 месяцев назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

CVSS3: 6.4
redhat
2 месяца назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

CVSS3: 6.4
nvd
около 2 месяцев назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

suse-cvrf
19 дней назад

Security update for sssd

suse-cvrf
21 день назад

Security update for sssd

EPSS

Процентиль: 2%
0.00121
Низкий