Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-68743

Опубликовано: 04 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sssdfixed2.13.1-2package
sssdno-dsatrixiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2509760

  • Fixed by: https://github.com/SSSD/sssd/commit/bef9d12617f22335e65447609a2724a68c1bf68a (master)

  • Fixed by: https://github.com/SSSD/sssd/commit/1ea0f2da77947598165da2b84202d355f43c9aa1 (sssd-2-13 branch)

EPSS

Процентиль: 1%
0.00093
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

CVSS3: 5.5
redhat
около 2 месяцев назад

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

CVSS3: 5.5
nvd
около 2 месяцев назад

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

suse-cvrf
26 дней назад

Security update for sssd

CVSS3: 5.5
github
около 2 месяцев назад

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

EPSS

Процентиль: 1%
0.00093
Низкий