A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read when processed by functions like snprintf(). A local attacker could potentially trigger this vulnerability by initiating a crafted passkey authentication request, causing the SSSD PAM responder to crash, resulting in a local Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade sssd-common-pac-debuginfoUpgrade sssd-dbusUpgrade sssd-adUpgrade libsss_idmap-debuginfoUpgrade sssd-krb5-commonUpgrade sssd-client-debuginfoUpgrade sssd-dbus-debuginfoUpgrade sssd-krb5-common-debuginfoUpgrade libsss_simpleifp-debuginfoUpgrade libipa_hbac-debuginfoUpgrade python3-sss-murmurUpgrade sssd-krb5-debuginfoUpgrade sssd-winbind-idmapUpgrade sssd-commonUpgrade libsss_idmap-develUpgrade libipa_hbac-develUpgrade sssd-ipaUpgrade sssd-idp-debuginfoUpgrade python3-sssdconfigUpgrade sssd-common-debuginfoUpgrade sssd-common-pacUpgrade sssd-debuginfoUpgrade sssd-ad-debuginfoUpgrade sssd-ipa-debuginfoUpgrade libsss_nss_idmap-debuginfoUpgrade python3-libsss_nss_idmap-debuginfoUpgrade libsss_certmap-debuginfoUpgrade libipa_hbacUpgrade sssd-nfs-idmapUpgrade sssd-proxyUpgrade libsss_nss_idmapUpgrade sssd-nfs-idmap-debuginfoUpgrade libsss_sudoUpgrade python3-sss-murmur-debuginfoUpgrade sssd-kcmUpgrade sssd-debugsourceUpgrade python3-libipa_hbacUpgrade sssd-proxy-debuginfoUpgrade libsss_simpleifp-develUpgrade sssd-tools-debuginfoUpgrade python3-sss-debuginfoUpgrade sssd-krb5Upgrade python3-libsss_nss_idmapUpgrade libsss_autofsUpgrade sssd-ldapUpgrade python3-libipa_hbac-debuginfoUpgrade libsss_simpleifpUpgrade libsss_nss_idmap-develUpgrade libsss_sudo-debuginfoUpgrade libsss_certmapUpgrade sssd-idpUpgrade sssd-clientUpgrade libsss_autofs-debuginfoUpgrade sssdUpgrade python3-sssUpgrade libsss_idmapUpgrade sssd-toolsUpgrade libsss_certmap-develUpgrade sssd-winbind-idmap-debuginfoUpgrade sssd-ldap-debuginfoUpgrade sssd-kcm-debuginfo | Jul 21, 2026 | Apr 15, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 15, 2026 |
| Ubuntu | — | Upgrade sssd | Jun 2, 2026 | Jun 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub