A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-sss-murmurUpgrade libipa_hbac-develUpgrade sssd-adUpgrade libsss_sudoUpgrade sssd-ipaUpgrade sssd-ldapUpgrade libsss_nss_idmap-develUpgrade libsss_simpleifpUpgrade sssdUpgrade python-sssUpgrade libsss_certmap-develUpgrade sssd-commonUpgrade sssd-polkit-rulesUpgrade sssd-libwbclient-develUpgrade libsss_idmap-develUpgrade sssd-common-pacUpgrade libsss_simpleifp-develUpgrade python-sssdconfigUpgrade sssd-krb5-commonUpgrade libsss_certmapUpgrade python-libsss_nss_idmapUpgrade sssd-kcmUpgrade sssd-clientUpgrade sssd-dbusUpgrade sssd-debuginfoUpgrade python-libipa_hbacUpgrade libipa_hbacUpgrade sssd-proxyUpgrade sssd-libwbclientUpgrade libsss_idmapUpgrade sssd-toolsUpgrade sssd-krb5Upgrade sssd-winbind-idmapUpgrade libsss_nss_idmapUpgrade libsss_autofs | Aug 5, 2026 | Aug 5, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 9, 2026 |
| Ubuntu | — | Upgrade libpam-sssUpgrade sssd-common | Sep 2, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub