CVE-2026-104030: Sssd: sssd: denial of service via out-of-bounds read during passkey parsing
A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting authentication services.
Other sources
AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: OOB Read in sssauthunpackpasskeyblob from Unbounded Parsing of SSSAUTHTOKTYPEPASSKEYKRB: a malformed length-delimited passkey blob that omits required in-bounds NUL terminators can be parsed past the provided buffer, causing a locally triggerable out-of-bounds read and likely denial of service in the SSSD PAM responder. Requirements to exploit: Local access to a system using the SSSD PAM responder, plus the ability to submit a crafted SSSAUTHTOKTYPEPASSKEYKRB blob without in-bounds NUL terminators. The available code context indicates this parsing occurs during PAM request handling before later trust-based restrictions, so ordinary local triggering appears plausible in default deployments. Component affected: sssd-2.12.0-1.el10, src/util/authtok.c, sssauthunpackpasskeyblob(); attacker-controlled ingress is via the PAM responder path in src/responder/pam/pamsrvcmd.c Version affected: sssd-2.12.0-1.el10 Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - 5.5 (MEDIUM) AV:L - Exploitation requires local access to a system that can reach the SSSD PAM responder. AC:L - The malformed input is straightforward: the attacker supplies a passkey blob with missing in-bounds '\0' terminators. PR:N - Available evidence indicates the PAM responder socket is intended to be reachable by ordinary local PAM clients and the affected parsing occurs before trust-based restrictions; deployments that further restrict local access may reduce exposure. UI:N - No separate user interaction is required once the crafted request is sent. S:U - The impact is confined to the vulnerable SSSD component. C:N - No confidentiality impact is established from the available evidence. I:N - No integrity impact is established from the available evidence. A:H - The demonstrated outcome is an out-of-bounds read that can crash or destabilize the authentication responder path. Impact: Moderate. Based on Red Hat's severity guidance, this issue has a credible local availability impact in a core authentication component, but the established effect is not remote, does not show privilege escalation, and does not demonstrate system compromise or arbitrary code execution. That makes it more serious than Low, but not a fit for Important or Critical. Embargo: no Reason: The current evidence supports a local denial-of-service issue with no demonstrated confidentiality, integrity, or code execution impact, and moderate/low issues of this type typically do not require embargo handling. Acknowledgement: Aisle Research Vulnerability Details: sssauthunpackpasskeyblob() parses a passkey blob as a sequence of C strings, but it receives only const uint8t blob and no length parameter. The function therefore trusts in-band '\0' terminators and walks past the caller-provided buffer if they are missing. c errnot sssauthunpackpasskeyblob(TALLOCCTX memctx, const uint8t blob, char prompt, char key, char pin) { sizet len = 0; ... prompt = tallocstrdup(memctx, (const char ) blob + len); len += strlen(prompt) + 1; key = tallocstrdup(memctx, (const char ) blob + len); len += strlen(key) + 1; ... } extractauthtokv2() accepts authtokendata together with authtokenlength, and the SSSAUTHTOKTYPEPASSKEYKRB path passes that length into sssauthtoksetpasskeyfromblob(tok, data, len). However, sssauthtoksetpasskeyfromblob() then calls sssauthunpackpasskeyblob(tmpctx, data, &prompt, &key, &pin);, so the explicit length is discarded before parsing. By contrast, sssauthunpack2fablob() and sssauthunpackscblob() both take bloblen and validate bounds. The available materials establish an out-of-bounds read and a realistic responder crash. An information disclosure effect is theoretically possible for this bug class, but no practical disclosure path is demonstrated here, so the supported impact is local denial of service. Steps to reproduce: 1. Build sssd-2.12.0-1.el10 with AddressSanitizer enabled, for example with -fsanitize=address. 2. Add a cmocka test under src/tests/cmocka/testauthtok.c that calls sssauthtokset(tok, SSSAUTHTOKTYPEPASSKEYKRB, blob, bloblen). 3. Use a blob with no '\0' inside bloblen, for example { 't','r','u','e','K','E','Y','D','A','T','A' } with bloblen = 11. 4. Run the affected unit test. 5. Observe an ASan invalid read originating from strlen()/tallocstrdup() in sssauthunpackpasskeyblob(). This reproducer uses only local code paths and does not depend on external services. Mitigation: No complete runtime mitigation is established from the available information. Until a fixed package is available, reducing access to the local PAM responder interface to trusted users can lower exposure where that is operationally possible, but default responder permissions are designed to allow ordinary local PAM clients. Proposed Fix: Pass the blob length into sssauthunpackpasskeyblob() and replace unbounded string parsing with memchr()-bounded extraction so the passkey parser behaves like the other bounded blob unpackers. diff diff --git a/src/util/authtok.c b/src/util/authtok.c index 0000000..0000000 100644 — a/src/util/authtok.c +++ b/src/util/authtok.c @@ -690,21 +690,43 @@ errnot sssauthunpackpasskeyblob(TALLOCCTX memctx, const uint8t blob, + const uint8t blob, sizet bloblen, char prompt, char key, char pin) {
sizet len = 0; + const uint8t p = blob; + sizet rem = bloblen; + const uint8t end; + sizet flen; char prompt; char key; char pin;
prompt = tallocstrdup(memctx, (const char ) blob + len); + if (blob == NULL || prompt == NULL || key == NULL || pin == NULL) { + return EINVAL; + } + + end = memchr(p, '\0', rem); + if (end == NULL) return EINVAL; + flen = (sizet)(end - p); + prompt = tallocstrndup(memctx, (const char )p, flen); if (prompt == NULL) return ENOMEM;
len += strlen(prompt) + 1; + p += flen + 1; rem -= flen + 1;
key = tallocstrdup(memctx, (const char ) blob + len); + end = memchr(p, '\0', rem); + if (end == NULL) { tallocfree(prompt); return EINVAL; } + flen = (sizet)(end - p); + key = tallocstrndup(memctx, (const char )p, flen); if (key == NULL) { tallocfree(prompt); return ENOMEM; }
len += strlen(key) + 1; + p += flen + 1; rem -= flen + 1;
if ((strcasecmp(prompt, "true") == 0)) { pin = tallocstrdup(memctx, (const char ) blob + len); + end = memchr(p, '\0', rem); + if (end == NULL) { + tallocfree(prompt); + tallocfree(key); + return EINVAL; + } + flen = (sizet)(end - p); + pin = tallocstrndup(memctx, (const char )p, flen); if (pin == NULL) { tallocfree(prompt); tallocfree(key); @@ -792,7 +814,7 @@ static errnot sssauthtoksetpasskeyfromblob(struct sssauthtoken tok,
ret = sssauthunpackpasskeyblob(tmpctx, data, &prompt, &key, &pin); + ret = sssauthunpackpasskeyblob(tmpctx, data, len, &prompt, &key, &pin); @@ -854,7 +876,8 @@ errnot sssauthtokgetpasskey(TALLOCCTX memctx,
ret = sssauthunpackpasskeyblob(memctx, tok->data, &prompt, &key, &pin); + ret = sssauthunpackpasskeyblob(memctx, tok->data, tok->length, + &prompt, &key, &pin);
------ This report was generated using AI technology. Always review AI-generated content prior to use
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the local SSSD PAM responder interface to trusted users to lower exposure where operationally possible.
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user with low privileges can exploit it by submitting a specially crafted passkey authentication token. Remote exploitation is not indicated by the provided vector.
What is required to trigger the denial of service?
The attacker needs to provide a passkey authentication token that lacks null terminators. Processing that token can make the authentication service read beyond the supplied buffer and crash.
What is the operational impact if exploitation succeeds?
The affected authentication service can crash, disrupting authentication services. The provided impact vector indicates availability impact only, with no confidentiality or integrity impact stated.