Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If automount map integration via SSSD is not required, disable the autofs responder service: 1. Stop and mask the socket-activated service: ```bash systemctl stop sssd-autofs.socket sssd-autofs.service systemctl mask sssd-autofs.socket ``` 2. If `autofs` is explicitly defined in `/etc/sssd/sssd.conf`, remove `autofs` from the `services` directive under the `[sssd]` section and restart the SSSD service: ```bash systemctl restart sssd ``` Caveats: Disabling the responder prevents SSSD from resolving automount maps. Warning: Modifying these configurations and restarting SSSD will disrupt active automount operations and may temporarily impact identity lookups during the service restart.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS). | |
| Title | Sssd: sssd: denial of service via packet length underflow in autofs responder | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T00:12:24.661Z
Reserved: 2026-10-01T17:22:37.377Z
Link: CVE-2026-104037
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-125
Out-of-bounds Read