Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12610

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

Отчет

This Moderate impact use-after-free flaw in the SSSD PAM responder can lead to a denial of service during YubiKey authentication, causing the process to crash and disrupt user access. While there is a theoretical potential for privilege escalation, exploitation is considered difficult due to the specific conditions required, which involve an attacker controlling smartcard contents during an active authentication attempt.

Меры по смягчению последствий

Configure the sssd systemd service to automatically restart on failure. This ensures authentication remains available even if an attacker triggers the denial-of-service crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10pamFix deferred
Red Hat Enterprise Linux 10sssdFix deferred
Red Hat Enterprise Linux 6pamFix deferred
Red Hat Enterprise Linux 6sssdOut of support scope
Red Hat Enterprise Linux 7pamFix deferred
Red Hat Enterprise Linux 7sssdOut of support scope
Red Hat Enterprise Linux 8pamFix deferred
Red Hat Enterprise Linux 8sssdFix deferred
Red Hat Enterprise Linux 9pamFix deferred
Red Hat Enterprise Linux 9sssdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2490288sssd: Use-after-free crash in SSSD' 'sssd_pam' process

EPSS

Процентиль: 2%
0.00121
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 2 месяцев назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

CVSS3: 6.4
nvd
около 2 месяцев назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.

CVSS3: 6.4
debian
около 2 месяцев назад

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD ...

suse-cvrf
19 дней назад

Security update for sssd

suse-cvrf
21 день назад

Security update for sssd

EPSS

Процентиль: 2%
0.00121
Низкий

6.4 Medium

CVSS3