OESA-2026-3648
Dashboard / Vulnerabilities / OESA-2026-3648
Summary: sssd security update
Details: Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. Security Fix(es): A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.(CVE-2026-68744)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3648, https://nvd.nist.gov/vuln/detail/CVE-2026-68744
Affected packages
Package
Name: sssd
Purl: pkg:rpm/openEuler/sssd&distro=openEuler-20.03-LTS-SP4
Affected ranges
Type: ECOSYSTEM
Events:
