Sceawere

Vulnerability Detail

CVE-2026-104029UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSSD Autofs Out-of-Bounds Read

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
1h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-05T20:17:08.487Z",
  "pubdate": "2026-10-05T20:17:08.487Z",
  "executiveSummary": "A memory safety vulnerability has been identified in the SSSD (System Security Services Daemon) autofs responder. The flaw is characterized as an out-of-bounds (OOB) memory read resulting from improper buffer offset calculations during the parsing of incoming requests via the UNIX socket.\nThis vulnerability poses a significant risk to system availability, as a local attacker can trigger the defect to force a process crash, leading to a Denial of Service (DoS) condition. The vulnerability is restricted to the local environment and does not provide an immediate vector for remote code execution or privilege escalation based on the current disclosure.\nThe attack requires the adversary to have local access to the system, allowing them to interact directly with the vulnerable autofs responder UNIX socket. By sending a specially crafted request, the attacker exploits the flawed parsing logic, causing the service to access memory outside of its intended bounds. Organizations utilizing SSSD with autofs enabled should prioritize remediation to ensure service continuity and prevent potential instability in critical identity and mount management services.",
  "technicalDetails": "The vulnerability resides within the SSSD autofs responder component, specifically in the logic responsible for parsing incoming requests received via the service's UNIX domain socket. The root cause is a deficiency in the bounds checking and offset calculation logic performed during the deserialization or processing of request structures. When the autofs responder processes an incoming message, it fails to properly validate the length or structure of the data against the allocated buffer size.\nThe attack flow initiates when a local user crafts a malicious packet structured to trigger an incorrect memory offset calculation. Upon the SSSD autofs responder receiving this packet, the internal parsing routines perform pointer arithmetic that drifts outside the intended buffer address space. Because the service attempts to read data from these invalid memory addresses, the process triggers a segmentation fault or a similar memory access violation.\nThe exploitation method relies on the deterministic nature of the parser's offset logic. By carefully crafting the input buffer metadata—such as length fields or specific header parameters—the attacker forces the pointer to move beyond the designated heap or stack memory allocated for the responder’s transaction buffer. The subsequent read operation is intercepted by the system's memory management unit (MMU), which terminates the process to prevent undefined behavior and potential data leakage, effectively achieving a crash.\nThe impact of this vulnerability is primarily focused on service availability. Because SSSD is a critical service for identity management and authentication, the instability of the autofs responder can disrupt dynamic mount management, affecting any applications or users relying on autofs services. While the current vector leads to a process crash (DoS), the nature of the OOB read implies that further research might reveal potential for information disclosure if the memory contents could be returned in a response before the process terminates.\nThe vulnerability requires local access, as the responder listens on a UNIX socket, which typically restricts interactions to processes running on the local host. Privilege requirements depend on the filesystem permissions configured for the specific UNIX socket used by the SSSD autofs responder. If the socket is readable by low-privileged users, the impact is elevated, as non-privileged local attackers can degrade service performance or availability. No network exposure is inherent to this flaw, as UNIX sockets are local-only inter-process communication mechanisms."
}
CVE-2026-104029: SSSD Autofs Out-of-Bounds Read (LOW Severity, CVSS: 3.3) | Sceawere