Sceawere
Vulnerability Detail
CVE-2026-104030UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSSD Passkey Memory Corruption DoS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 1h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting authentication services.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-05T20:17:08.637Z",
"pubdate": "2026-10-05T20:17:08.637Z",
"executiveSummary": "A memory corruption vulnerability exists within the System Security Services Daemon (sssd) related to its handling of passkey authentication tokens.\nThe flaw originates from an out-of-bounds read occurring when the authentication service processes a malformed token lacking the necessary null-terminator.\nA local, authenticated, or unauthenticated user capable of interacting with the sssd authentication interface can trigger this condition by submitting a specifically crafted input.\nSuccessful exploitation results in the abnormal termination of the sssd process, leading to a localized Denial of Service (DoS) for all services relying on sssd for identity and authentication lookups.\nThe vulnerability requires no elevated privileges to initiate, posing a significant risk to system availability in environments where passkey authentication is active.\nAs the service crashes upon encountering the malformed buffer, it directly disrupts essential authentication and authorization workflows, potentially leading to administrative lockouts or service outages across the affected host.",
"technicalDetails": "The root cause of this vulnerability is an improper input validation flaw within the sssd passkey authentication logic. Specifically, the service fails to verify the structural integrity of the passkey token provided by the user before performing memory-sensitive operations.\nThe vulnerability manifests when the sssd authentication component reads the incoming passkey token into a memory buffer. If the token is crafted to lack a required null terminator, the string-handling functions—which expect C-style strings terminated by a null byte—continue to read memory addresses beyond the designated boundary of the input buffer.\nThis out-of-bounds read operation occurs because the internal logic assumes the presence of a null terminator, causing the pointer to increment into adjacent memory segments. When the process attempts to access or parse this memory, it triggers a segmentation fault or a similar memory access violation, leading to the immediate termination of the sssd daemon process.\nThe attack flow involves a local user interfacing with the sssd service, typically through standard authentication request channels. The attacker transmits a payload containing a token string that is intentionally malformed by omitting the expected null terminator. Upon receiving this payload, the sssd service allocates a memory buffer, copies the non-null-terminated string, and subsequently executes operations that traverse the memory past the end of the buffer.\nSince the sssd daemon is often a critical system component responsible for centralized identity management (e.g., LDAP, AD, or local account lookups), the crash of this process interrupts the entire authentication stack on the local host. This effectively prevents any further authentication requests from succeeding, resulting in a system-wide Denial of Service.\nBecause the vulnerability is triggered by input provided to the authentication processing function, it does not require prior administrative or root access; however, it is constrained to a local context where the attacker can interact with the authentication daemon. The exploit does not require complex heap grooming or sophisticated memory corruption primitives; the lack of bounds checking on the buffer traversal is sufficient to cause the process to crash reliably."
}