Medium [CVE-2026-104039] Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder
This medium-severity Red Hat Linux advisory covers CVE-2026-104039 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services.
When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer.
An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate. This vulnerability is rated as Moderate because exploitation requires local access, specific non-default configuration, and an established session, resulting solely in a denial of service.
The flaw is only reachable when SSSD's PAM responder has GSSAPI authentication explicitly configured and enabled for specific services. Furthermore, triggering the condition requires an authenticated local user to complete an initial GSSAPI context handshake and subsequently submit an additional request over the same connection.
Because exploitation crashes the PAM responder process without compromising system confidentiality or integrity, the overall risk is reduced. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Weakness: CWE-825.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · medium-confidence parse· fetched 41 minutes ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · medium-confidence parse· fetched 41 minutes ago·verify at source
Mitigation
The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.
Official advisory · medium-confidence parse· fetched 41 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.