Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90995

Опубликовано: 14 сент. 2026
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the pam_app_services configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

Отчет

This Moderate impact denial of service vulnerability in SSSD's PAM responder requires local access and a non-default pam_app_services configuration. An authenticated local attacker can send a crafted PAM request, leading to a NULL pointer dereference and crashing the PAM responder, thereby disrupting authentication services. The default SSSD configuration is not affected.

Меры по смягчению последствий

To mitigate this issue, avoid configuring pam_app_services in the [pam] section of /etc/sssd/sssd.conf if it is not operationally required. If pam_app_services is configured, remove or comment out the pam_app_services line and restart the sssd service. Example:

# /etc/sssd/sssd.conf [pam] # pam_app_services = app_svc

After modifying the configuration, restart the SSSD service: systemctl restart sssd Note that restarting the SSSD service may temporarily interrupt authentication and authorization services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sssdFix deferred
Red Hat Enterprise Linux 6sssdOut of support scope
Red Hat Enterprise Linux 7sssdFix deferred
Red Hat Enterprise Linux 8sssdFix deferred
Red Hat Enterprise Linux 9sssdFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2479464sssd: SSSD: Local denial of service due to NULL pointer dereference in PAM responder

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
2 дня назад

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

CVSS3: 5.5
nvd
2 дня назад

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

CVSS3: 5.5
debian
2 дня назад

A flaw was found in SSSD (System Security Services Daemon). A local at ...

CVSS3: 5.5
github
2 дня назад

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

5.5 Medium

CVSS3