Unrated severityNVD Advisory· Published Oct 29, 2015· Updated May 6, 2026
CVE-2015-5292
CVE-2015-5292
Description
Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.
Affected products
17cpe:2.3:a:fedoraproject:sssd:1.10.0:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:fedoraproject:sssd:1.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.6:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.11.7:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.4:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.13.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- permalink.gmane.org/gmane.linux.redhat.sssd.user/3422nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-October/169110.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-October/169597.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-October/169613.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2019.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2355.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlnvd
- www.securityfocus.com/bid/77529nvd
- www.securitytracker.com/id/1034038nvd
- bugzilla.redhat.com/show_bug.cginvd
- fedorahosted.org/sssd/attachment/ticket/2803/0001-Fix-memory-leak-in-sssdpac_verify.patchnvd
- fedorahosted.org/sssd/ticket/2803nvd
- fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1nvd
News mentions
0No linked articles in our index yet.