Описание
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
Отчет
This Moderate impact use-after-free flaw in the SSSD PAM responder can lead to a denial of service during YubiKey authentication, causing the process to crash and disrupt user access. While there is a theoretical potential for privilege escalation, exploitation is considered difficult due to the specific conditions required, which involve an attacker controlling smartcard contents during an active authentication attempt.
Меры по смягчению последствий
Configure the sssd systemd service to automatically restart on failure. This ensures authentication remains available even if an attacker triggers the denial-of-service crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | pam | Fix deferred | ||
| Red Hat Enterprise Linux 10 | sssd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | pam | Fix deferred | ||
| Red Hat Enterprise Linux 6 | sssd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pam | Fix deferred | ||
| Red Hat Enterprise Linux 7 | sssd | Out of support scope | ||
| Red Hat Enterprise Linux 8 | pam | Fix deferred | ||
| Red Hat Enterprise Linux 8 | sssd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | pam | Fix deferred | ||
| Red Hat Enterprise Linux 9 | sssd | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD ...
EPSS
6.4 Medium
CVSS3