CVE-2026-104042: Sssd: sssd: denial of service via out-of-bounds read in pam responder

Published May 18, 2026
·
Updated

A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing the token, causing the PAM responder to crash.

Other sources

AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: Local DoS in PAM responder via out-of-bounds read on zero-length string auth tokens (extractauthtokv2 -> sssauthtoksetstring): a crafted PAM v2/v3 request can pass a zero-length string-backed auth token into an unbounded strlen() on packet-backed memory and may crash the PAM responder. Requirements to exploit: An attacker needs local access to the host and the ability to send a syntactically valid PAM v2/v3 request to the PAM responder socket. In the source tree, the PAM responder uses SCKTRSPUMASK 0111, which makes unprivileged local reachability plausible, although practical exposure can still vary with deployment and service configuration. Component affected: sssd-2.12.0-1.el10, PAM responder request parsing in src/responder/pam/pamsrvcmd.c (extractauthtokv2()), reaching src/util/authtok.c (sssauthtoksetstring()). Version affected: sssd-2.12.0-1.el10 Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - 5.5 (MEDIUM) AV:L - The issue is triggered from the local host by sending a crafted PAM request to the responder socket. AC:L - The malformed input is straightforward: a validly framed request with size = 4 and no token bytes for a string-backed auth token type. PR:L - Exploitation requires only an unprivileged local execution context that can connect to the PAM responder socket. UI:N - No victim interaction is required once the attacker can reach the socket. S:U - The impact is confined to the PAM responder's own security scope. C:N - No confidentiality impact is established from the available technical evidence. I:N - No integrity impact is established from the available technical evidence. A:H - The out-of-bounds read can crash the responder and cause a meaningful loss of PAM responder availability. Impact: Moderate. The issue can affect availability for reachable local clients, but it is not a remote flaw, no privilege escalation is shown, and no confidentiality or integrity impact is established. Under the Red Hat severity guidance, that fits Moderate more closely than Important or Critical. Embargo: no Reason: This is a local denial-of-service issue with configuration-dependent reachability and no demonstrated confidentiality, integrity, or privilege-escalation impact. Prompt remediation is more appropriate than embargo handling. Acknowledgement: Aisle Research Vulnerability Details: In extractauthtokv2(), authtokenlength is derived as datasize - sizeof(uint32t). When a PAM v2/v3 request supplies size = 4, the parser accepts authtokenlength == 0 and still passes the packet-backed pointer into sssauthtokset() for the string-backed auth token types SSSAUTHTOKTYPE2FASINGLE, SSSAUTHTOKTYPEOAUTH2, SSSAUTHTOKTYPEPASSKEY, SSSAUTHTOKTYPEPASSKEYREPLY, and SSSAUTHTOKTYPEPAMSTACKED. That path reaches sssauthtoksetstring(), which contains the following logic: c if (len == 0) { len = strlen(str); } else { while (len > 0 && str[len - 1] == '\0') len--; } Here, str points into the PAM request buffer rather than to a guaranteed NUL-terminated string. Valid PAM framing does not provide a nearby terminator for this path; the recorded end marker is SSSENDOFPAMREQUEST 0x4950414d, so strlen() can continue reading beyond the packet boundary until a zero byte is encountered elsewhere in memory. This creates an out-of-bounds read with plausible responder crash behavior, which is sufficient for a local denial of service. The issue is best understood as missing input validation on zero-length typed string tokens leading to an out-of-bounds read. Steps to reproduce: 1. Build SSSD with ASan (-fsanitize=address) for deterministic detection. 2. Send a PAM protocol v2/v3 request with valid SSSSTARTOFPAMREQUEST ... SSSENDOFPAMREQUEST framing. 3. Include SSSPAMITEMAUTHTOK with size = 4, authtokentype = SSSAUTHTOKTYPE2FASINGLE (or SSSAUTHTOKTYPEOAUTH2, SSSAUTHTOKTYPEPASSKEY, SSSAUTHTOKTYPEPASSKEYREPLY, SSSAUTHTOKTYPEPAMSTACKED), and no token bytes. 4. Follow the parser path pamforwarderparsedata() -> pamparseindatav2/v3() -> extractauthtokv2() -> sssauthtokset(..., len=0) -> sssauthtoksetstring() -> strlen() on the request-backed pointer. 5. Under ASan, observe an out-of-bounds read; without ASan, the responder may crash, resulting in a local denial of service. Mitigation: Restrict PAM responder socket access to trusted local clients where possible. Deployments that already prevent unprivileged local clients from reaching the responder reduce exploitability until a code fix is applied. Proposed Fix: Reject zero-length payloads for the affected string-backed auth token types in extractauthtokv2() before they reach sssauthtoksetstring(). diff — a/src/responder/pam/pamsrvcmd.c +++ b/src/responder/pam/pamsrvcmd.c @@ -204,6 +204,18 @@ static int extractauthtokv2(struct sssauthtoken tok, case SSSAUTHTOKTYPE2FA: case SSSAUTHTOKTYPESCPIN: case SSSAUTHTOKTYPESCKEYPAD: + case SSSAUTHTOKTYPEPASSKEYKRB: + ret = sssauthtokset(tok, authtokentype, + authtokendata, authtokenlength); + break; + case SSSAUTHTOKTYPE2FASINGLE: + case SSSAUTHTOKTYPEOAUTH2: + case SSSAUTHTOKTYPEPASSKEY: + case SSSAUTHTOKTYPEPASSKEYREPLY: + case SSSAUTHTOKTYPEPAMSTACKED: + if (authtokenlength == 0) { + return EINVAL; + } ret = sssauthtokset(tok, authtokentype, authtokendata, authtokenlength); break; case SSSAUTHTOKTYPEPASSKEYKRB:

ret = sssauthtokset(tok, authtokentype,

authtokendata, authtokenlength);

break;

A secondary guard in sssauthtoksetstring() to reject len == 0 on untrusted call paths would provide additional defense in depth. ------ This report was generated using AI technology. Always review AI-generated content prior to use

— Red Hat

Affected Software

1 affected component
redhat/sssd=2.12.0-1.el10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict PAM responder socket access to trusted local clients to reduce reachability of the vulnerable request-parsing path.

    SSSD PAM responder socket socket access = trusted local clients only
  2. Compensating control

    Reject zero-length payloads for string-backed authentication token types in extract_authtok_v2() before they reach sss_authtok_set_string(), including SSS_AUTHTOK_TYPE_2FA_SINGLE, SSS_AUTHTOK_TYPE_OAUTH2, SSS_AUTHTOK_TYPE_PASSKEY, SSS_AUTHTOK_TYPE_PASSKEY_REPLY, and SSS_AUTHTOK_TYPE_PAM_STACKED.

Event History

May 18, 2026
Data Sourced
via Red Hat·03:47 AM
DescriptionSeverityAffected Software
Oct 6, 2026
CVE Published
via MITRE·01:02 AM
Data Sourced
via MITRE·01:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically trigger this issue?

An attacker needs local access to the host and the ability to send a syntactically valid PAM v2 or v3 request to the PAM responder socket. The responder socket's source-tree umask makes unprivileged local reachability plausible, but actual exposure can vary by deployment and service configuration.

2

What must an attacker send to cause the denial of service?

The request must contain a zero-length, string-backed authentication token. Missing validation allows processing to reach an unbounded strlen() on packet-backed memory, which may crash the PAM responder.

3

What is the operational impact of exploitation?

The PAM responder can crash, causing a denial of service. The provided information identifies no confidentiality or integrity impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203