Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-104038

CVE-2026-104038: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.9

    Medium [CVE-2026-104038] Sssd: sssd: denial of service via missing sid extension in certificate mapping

    CVE-2026-104038Source published Source updated

    A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations. This vulnerability is rated as Moderate impact because triggering the denial of service requires an uncommon, non-default certificate mapping configuration. SSSD deployments are only susceptible if explicitly configured to use LDAPU1 mapping rules that expand SID or RID templates. Furthermore, an attacker must supply a certificate lacking the expected Microsoft SID extension to trigger the crash, confining…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7
    • Red Hat Enterprise Linux 8

    33 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • To mitigate this issue, reconfigure SSSD certificate mapping rules to avoid using `{sid}` or `{sid.rid}` expansion templates within `LDAPU1` mapping rules. 1. Inspect `/etc/sssd/sssd.conf` and any configuration snippets in `/etc/sssd/conf.d/` for `maprule` directives that expand `{sid}` or `{sid.rid}`. 2. Modify the mapping rules to use alternative certificate attributes or ensure certificates without the Microsoft SID extension (OID 1.3.6.1.4.1.311.25.2) are rejected before reaching the certificate mapping evaluation. 3. Restart the SSSD service to apply the configuration changes: ``` systemctl restart sssd ``` Warning: Restarting the SSSD service temporarily interrupts identity lookup and authentication requests on the system. Modifying active certificate mapping rules may prevent certificate authentication for users whose accounts rely strictly on SID-based mapping.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery