Количество 8
Количество 8
CVE-2026-68743
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
CVE-2026-68743
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
CVE-2026-68743
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
CVE-2026-68743
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...
SUSE-SU-2026:3797-1
Security update for sssd
GHSA-3v6f-w66g-3mv6
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
openSUSE-SU-2026:21748-1
Security update for sssd
SUSE-SU-2026:3899-1
Security update for sssd
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ... | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
SUSE-SU-2026:3797-1 Security update for sssd | 0% Низкий | 26 дней назад | ||
GHSA-3v6f-w66g-3mv6 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21748-1 Security update for sssd | 17 дней назад | |||
SUSE-SU-2026:3899-1 Security update for sssd | 20 дней назад |
Уязвимостей на страницу