Medium [CVE-2026-104038] Sssd: sssd: denial of service via missing sid extension in certificate mapping
This medium-severity Red Hat Linux advisory covers CVE-2026-104038 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension.
In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations.
This vulnerability is rated as Moderate impact because triggering the denial of service requires an uncommon, non-default certificate mapping configuration. SSSD deployments are only susceptible if explicitly configured to use LDAPU1 mapping rules that expand SID or RID templates.
Furthermore, an attacker must supply a certificate lacking the expected Microsoft SID extension to trigger the crash, confining the operational impact to certificate-driven lookup and authentication flows. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- To mitigate this issue, reconfigure SSSD certificate mapping rules to avoid using `{sid}` or `{sid.rid}` expansion templates within `LDAPU1` mapping rules. 1. Inspect `/etc/sssd/sssd.conf` and any configuration snippets in `/etc/sssd/conf.d/` for `maprule` directives that expand `{sid}` or `{sid.rid}`. 2. Modify the mapping rules to use alternative certificate attributes or ensure certificates without the Microsoft SID extension (OID 1.3.6.1.4.1.311.25.2) are rejected before reaching the certificate mapping evaluation. 3. Restart the SSSD service to apply the configuration changes: ``` systemctl restart sssd ``` Warning: Restarting the SSSD service temporarily interrupts identity lookup and authentication requests on the system. Modifying active certificate mapping rules may prevent certificate authentication for users whose accounts rely strictly on SID-based mapping.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.