SSSD: 20 Vulnerabilities Disclosed Together, Affecting Authentication and Identity Management
Key findings • 20 vulnerabilities disclosed for SSSD between October 5-6, 2026. • Multiple DoS vulnerabilities due to memory management, input validation, and cache issues. • Access contr…

Key findings
- 20 vulnerabilities disclosed for SSSD between October 5-6, 2026.
- Multiple DoS vulnerabilities due to memory management, input validation, and cache issues.
- Access control bypasses and information disclosure possible via Entra ID and LDAP configurations.
- Vulnerabilities primarily affect local users, impacting authentication and identity services.
- All disclosed vulnerabilities have been patched by the SSSD project.
- Issues span across PAM, NSS, autofs responders, KCM, and NFS idmap plugin.
On October 5-6, 2026, a batch of 20 medium and low severity vulnerabilities was disclosed for SSSD (System Security Services Daemon), impacting various authentication and identity management functionalities. These vulnerabilities, primarily affecting local users, range from denial-of-service (DoS) conditions to potential information disclosure and access bypasses. The disclosures highlight issues across multiple SSSD components, including its Pluggable Authentication Module (PAM) responder, Name Service Switch (NSS) responder, autofs responder, Kerberos Credential Manager (KCM), and its integration with Microsoft Entra ID and LDAP.
Several vulnerabilities stem from improper handling of memory and state management, leading to DoS conditions. CVE-2026-104046 and CVE-2026-104044 describe unbounded memory consumption and uninitialized pointer dereferencing, respectively, when Identity Provider (IdP) authentication or passkey authentication is enabled. Similarly, CVE-2026-104045 and CVE-2026-104037 detail DoS via race conditions and integer underflows in the autofs responder, leading to memory leaks or crashes. CVE-2026-104043 and CVE-2026-104033 also involve integer underflows and out-of-bounds memory reads in the NSS and autofs responders, respectively, causing DoS.
Further DoS vulnerabilities arise from inadequate input validation and cache management. CVE-2026-104041 describes how an unbounded negative cache in the NSS responder can be exploited by repeatedly requesting non-existent entries, leading to excessive memory usage. CVE-2026-104039 and CVE-2026-104010 point to issues in GSSAPI and Entra ID authentication, where cached connection state or improper input escaping can lead to DoS or information disclosure. CVE-2026-104035 details a DoS in the KCM responder due to failure to release cached objects during repeated credential operations, while CVE-2026-104034 highlights a use-after-free vulnerability during KCM ticket renewal. CVE-2026-104032 describes how missing authorization checks in the autofs responder can lead to DoS through repeated cache invalidation. CVE-2026-104029, a low-severity issue, involves an out-of-bounds memory read in the autofs responder due to improper buffer offset calculation.
Access control and authentication bypasses are also present. CVE-2026-104048 allows an authenticated user in a trusted domain to bypass access policies by exploiting how SSSD evaluates Host-Based Access Control (HBAC) rules with shared usernames. CVE-2026-104047 and CVE-2026-104040 detail how improper sanitization and escaping of search inputs when configured with Microsoft Entra ID can allow local users to manipulate directory queries for unauthorized information disclosure. CVE-2026-104038 describes a DoS when a certificate lacks an expected SID extension, causing SSSD to fail verification before processing. CVE-2026-104033 notes that SSSD fails to treat an LDAP expiration value of zero as expired, allowing users with expired accounts to bypass access controls. Finally, CVE-2026-104036 indicates a buffer overflow in the NFS idmap plugin when handling oversized cached entries.
The disclosed vulnerabilities were patched by the SSSD project. Users are advised to update to the latest versions to mitigate these risks. The batch of disclosures underscores the importance of rigorous input validation, secure memory management, and comprehensive state handling across SSSD's diverse authentication and identity management modules.
The vulnerabilities were disclosed on October 5-6, 2026. All identified issues have been addressed by the SSSD project.
Key Findings:
- 20 vulnerabilities disclosed for SSSD between October 5-6, 2026.
- Multiple DoS vulnerabilities due to memory management, input validation, and cache issues.
- Access control bypasses and information disclosure possible via Entra ID and LDAP configurations.
- Vulnerabilities primarily affect local users, impacting authentication and identity services.
- All disclosed vulnerabilities have been patched by the SSSD project.
- Issues span across PAM, NSS, autofs responders, KCM, and NFS idmap plugin.