REDHAT-BUG-2478662: Medium severity redhat/sssd vulnerability
AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: Unbounded openrequesttable growth in IdP PREAUTH can cause local DoS (memory exhaustion): repeated successful PREAUTH flows can retain stale per-request state in a process-lifetime hash table without a size bound, timeout, or proactive cleanup, allowing local memory exhaustion when AUTHENTICATE is never completed. Requirements to exploit: A local attacker must be able to reach a PAM authentication surface handled by sssd-2.12.0-1.el10 with IdP authentication enabled, repeatedly drive PREAUTH to a successful device-authorization reply, and stop before completing the matching AUTHENTICATE step for each returned usercode. Component affected: sssd-2.12.0-1.el10, IdP authentication backend in src/providers/idp/idpautheval.c (evaldeviceauthbuf()), src/providers/idp/idpauth.c (getstoredrequestdata()), and src/providers/idp/idpinit.c (sssmidpauthinit()). Version affected: sssd-2.12.0-1.el10 when IdP authentication is enabled and the PREAUTH device-authorization flow is reachable. Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - 6.2 (MEDIUM) AV:L - The attack requires local access to a PAM authentication surface on the affected host. AC:L - Once IdP authentication is enabled, repeatedly driving PREAUTH and withholding AUTHENTICATE is straightforward. PR:N - No prior privileges are required before attempting authentication. UI:N - No separate victim interaction is required. S:U - The impact remains within the same security scope. C:N - No confidentiality impact was established. I:N - No integrity impact was established. A:H - Persistent growth of stored request state can exhaust backend memory and disrupt authentication services. Impact: Moderate. This is a real availability issue on affected deployments, but it is local and configuration-dependent rather than a remote or default-path compromise. Based on Red Hat severity guidance, that fits Moderate better than Important or Critical. Embargo: no Reason: The demonstrated impact is local and availability-only, depends on IdP-enabled deployments, and has straightforward operational mitigation while a code fix is prepared. Acknowledgement: Aisle Research Vulnerability Details: In the IdP PREAUTH path, successful device-authorization replies allocate and store per-request state in openrequesttable with no size limit, timeout, or eviction in the shown path: c / src/providers/idp/idpautheval.c / openreq = talloczero(idpauthctx, struct idpopenreqdata); openreq->devicecodedata = tallocstrdup(openreq, (char ) buf); ret = sssptrhashadd(idpauthctx->openrequesttable, userdata->usercode, openreq, struct idpopenreqdata); The corresponding cleanup occurs only later in getstoredrequestdata() during SSSPAMAUTHENTICATE, where the entry is looked up by usercode and then freed. The table itself is created under authctx in sssmidpauthinit(), so it persists for backend lifetime. As a result, PREAUTH requests that successfully reach evaldeviceauthbuf() but never complete AUTHENTICATE can leave stale entries behind. Repeated successful PREAUTH flows that produce fresh usercode values can therefore grow the table over time, increasing backend RSS and potentially degrading or terminating the affected SSSD backend under memory pressure. The available evidence supports availability impact only; no confidentiality, integrity, or privilege-escalation impact was established. Steps to reproduce: 1. Configure a test domain with IdP auth enabled (idp options set; IdP provider active). 2. Start SSSD and identify the IdP backend PID. 3. Trigger many PREAUTH attempts that reach evaldeviceauthbuf() success, but never submit the matching OAuth2 usercode in AUTHENTICATE. 4. Observe growth during the run with while true; do ps -o pid,rss,cmd -p <pid>; sleep 2; done. Optional debug logs should show repeated successful PREAUTH handling with no matching AUTHENTICATE cleanup path. 5. Confirm memory is not reclaimed over time unless matching AUTHENTICATE happens. Prolonged runs can degrade or terminate the backend under memory pressure. Mitigation: Deployments that do not enable IdP authentication are not exposed to this path. Until a fix is available, disable the affected IdP authentication configuration where possible, restrict who can reach PAM services that exercise this flow, and restart the affected SSSD backend or service if memory growth is observed to reclaim accumulated entries. Proposed Fix: A minimal fix is to record request age, reject overly old stored requests, and bound the number of pending requests. diff diff --git a/src/providers/idp/idpprivate.h b/src/providers/idp/idpprivate.h index 3a2b0b7..e19f2d2 100644 — a/src/providers/idp/idpprivate.h +++ b/src/providers/idp/idpprivate.h @@ -51,6 +51,7 @@ requests. / struct idpopenreqdata { + timet createdat; char devicecodedata; };
diff --git a/src/providers/idp/idpautheval.c b/src/providers/idp/idpautheval.c index 7f6a9e2..3f0d8bc 100644 — a/src/providers/idp/idpautheval.c +++ b/src/providers/idp/idpautheval.c @@ -22,6 +22,7 @@ #include <errno.h> +#include <time.h> #include <jansson.h> @@ -41,6 +42,8 @@ errnot evaldeviceauthbuf(struct idpauthctx idpauthctx, struct sssidpoauth2 userdata = NULL; int ret; struct idpopenreqdata openreq = NULL; + const sizet maxopenrequests = 1024; + timet now; @@ -76,6 +79,13 @@ errnot evaldeviceauthbuf(struct idpauthctx idpauthctx, goto done; } + if (hashcount(idpauthctx->openrequesttable) >= maxopenrequests) { + DEBUG(SSSDBGOPFAILURE, "Too many pending IdP auth requests.\n"); + ret = ENOSPC; + goto done; + } + + now = time(NULL); openreq = talloczero(idpauthctx, struct idpopenreqdata); if (openreq == NULL) { @@ -83,6 +93,7 @@ errnot evaldeviceauthbuf(struct idpauthctx idpauthctx, ret = ENOMEM; goto done; } + openreq->createdat = now; diff --git a/src/providers/idp/idpauth.c b/src/providers/idp/idpauth.c index 28baf1c..2d1a644 100644 — a/src/providers/idp/idpauth.c +++ b/src/providers/idp/idpauth.c @@ -23,6 +23,7 @@ #include <security/pammodules.h> +#include <time.h> @@ -152,6 +153,7 @@ static const char getstoredrequestdata(TALLOCCTX memctx, const char usercode; sizet usercodelen; + const timet maxage = 300; @@ -176,6 +178,12 @@ static const char getstoredrequestdata(TALLOCCTX memctx, DEBUG(SSSDBGOPFAILURE, "Missing device code data.\n"); goto done; } + if (time(NULL) - openreq->createdat > maxage) { + DEBUG(SSSDBGOPFAILURE, "Stored device auth request expired.\n"); + senddata = NULL; + goto done; + } + This is intentionally minimal; a stronger fix would also proactively prune expired entries from the full table. ------ This report was generated using AI technology. Always review AI-generated content prior to use
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the affected IdP authentication configuration until a fix is available.
SSSD IdP authentication backend IdP authentication = disabled - Compensating control
Restrict which users or systems can reach the PAM authentication surface handled by the IdP-enabled SSSD backend.
- Compensating control
Implement the proposed IdP request-state safeguards: limit pending requests to 1024, record request age, reject requests older than 300 seconds, and proactively prune expired entries from the full table.
- Operational
If memory growth is observed, restart the affected SSSD backend or service to reclaim accumulated request state.