VYPR

SSSD

by Red Hat

Source repositories

CVEs (12)

  • CVE-2012-3462HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • CVE-2026-14476HigJul 7, 2026
    risk 0.45cvss 8.0epss 0.01

    A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root.…

  • CVE-2026-87853HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP…

  • CVE-2026-68743MedAug 4, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket,…

  • CVE-2026-90462MedSep 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache…

  • CVE-2018-16838MedMar 25, 2019
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

  • CVE-2017-12173MedJul 27, 2018
    risk 0.28cvss 4.3epss 0.01

    It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated…

  • CVE-2026-90996MedSep 14, 2026
    risk 0.26cvss 4.0epss 0.00

    A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This…

  • CVE-2026-90463MedSep 14, 2026
    risk 0.26cvss 4.0epss 0.00

    A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of…

  • CVE-2026-68744LowAug 4, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker…

  • CVE-2023-3758HigApr 18, 2024
    risk 0.00cvss 7.1epss 0.01

    A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

  • CVE-2013-0287Mar 21, 2013
    risk 0.00cvss —epss 0.02

    The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.