OESA-2026-3647
Dashboard / Vulnerabilities / OESA-2026-3647
OESA-2026-3647
Summary: sssd security update
Details: Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. Security Fix(es): A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.(CVE-2026-68742) A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.(CVE-2026-68744)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3647, https://nvd.nist.gov/vuln/detail/CVE-2026-68742, https://nvd.nist.gov/vuln/detail/CVE-2026-68744
Affected packages
Package
Name: sssd
Purl: pkg:rpm/openEuler/sssd&distro=openEuler-24.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
