REDHAT-BUG-2478980: Null Pointer Dereference
AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: NULL Pointer Dereference in expandsid() ({sid} / {sid.rid}) Can Crash SSSD in LDAPU1 Certmap Flows: a missing NULL check allows a certificate without Microsoft SID extension OID 1.3.6.1.4.1.311.25.2 to drive a NULL sidext into SID-based LDAPU1 certmap expansion and crash the SSSD certificate-mapping path. Requirements to exploit: The deployment must use certificate mapping with an LDAPU1 maprule that expands {sid} or {sid.rid}, and the attacker must be able to supply a syntactically valid certificate to that path. The certificate must omit OID 1.3.6.1.4.1.311.25.2. The available evidence supports denial of service where certificate input is attacker-controlled; it does not establish broader impact. Component affected: sssd-2.12.0-1.el10, certificate mapping in src/lib/certmap/ssscertmap.c (expandsid() / expandtemplate()) together with SID extraction in src/lib/certmap/ssscertcontentcrypto.c (getsidext()). Version affected: sssd-2.12.0-1.el10 when an LDAPU1 certmap rule uses {sid} or {sid.rid}. Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - 5.9 (MEDIUM) AV:N - In deployments exposing certificate-authentication or certificate-lookup flows to remote clients, the attacker can reach the vulnerable mapping path over the network. AC:H - Exploitation depends on a non-default but supported LDAPU1 SID-based certmap rule and on a certificate that omits the SID extension. PR:N - No prior privileges are required once the affected certmap flow is reachable. UI:N - No victim interaction is required; the service evaluates the certificate automatically. S:U - The crash affects the same SSSD security scope. C:N - No confidentiality impact is established by the available evidence. I:N - No integrity impact is established by the available evidence. A:H - The NULL dereference can terminate the SSSD process handling certificate mapping, denying authentication or lookup service until recovery. Impact: Moderate. Red Hat rates remote denial of service issues as Important when they can easily affect availability, but this case depends on a specific LDAPU1 SID-based certmap configuration rather than a default or broadly expected setup. The evidence supports availability impact only, so Moderate is a better fit. Embargo: no Reason: This is a configuration-dependent denial of service with straightforward mitigation and a small, self-contained fix. The available evidence does not show confidentiality, integrity, or code-execution impact. Acknowledgement: Aisle Research Vulnerability Details: Certificate parsing can succeed even when the Microsoft SID extension is absent. In that case getsidext() returns success without populating sidext, and expandtemplate() passes that pointer directly into expandsid(). The materials most directly establish the crash path for {sid.rid} via strrchr(NULL, '-'). {sid} should be covered by the same guard because the same NULL sid is also passed into tallocstrdup(ctx, sid). Supporting material indicates SID-based expansion is part of supported LDAPU1 handling, so this is a reachable configuration path rather than dead code. Relevant CWE: CWE-476. c static int expandsid(struct ssscertmapctx ctx, const char attrname, const char sid, char expanded) { char exp; char sep; if (attrname == NULL) { exp = tallocstrdup(ctx, sid); } else if (strcasecmp(attrname, "rid") == 0) { sep = strrchr(sid, '-'); if (sep == NULL || sep[1] == '\0') { CMDEBUG(ctx, "Unsupported SID string [%s].", sid); return EINVAL; } exp = tallocstrdup(ctx, sep+1); } else { CMDEBUG(ctx, "Unsupported attribute name [%s].", attrname); return EINVAL; } ... } ... } else if (strcmp("sid", parsedtemplate->name) == 0) { ret = expandsid(ctx, parsedtemplate->attrname, certcontent->sidext, &exp); } ... idx = X509getextbyOBJ(cert, sidextoid, -1); ASN1OBJECTfree(sidextoid); if (idx == -1) { / Extension most probably not available, no error. / return 0; } Steps to reproduce: 1. Configure a certmap rule using LDAPU1 SID expansion, for example maprule = LDAPU1:(objectsid={sid.rid}). 2. Ensure that rule is exercised by a real certificate lookup or authentication path, such as PAM, LDAP, or proxy-backed cert mapping. 3. Present a syntactically valid certificate that does not contain OID 1.3.6.1.4.1.311.25.2. 4. Trigger certificate mapping so ssscertmapgetsearchfilter() or ssscertmapexpandmappingrule() evaluates the rule. 5. Observe the NULL dereference in expandsid() and resulting process crash. The clearest reproduction is with {sid.rid}. Mitigation: Until a fix is shipped, avoid LDAPU1 certmap rules that expand {sid} or {sid.rid}. If SID-based mapping is required, reject certificates missing OID 1.3.6.1.4.1.311.25.2 before they reach the affected expansion path. Proposed Fix: Add an early NULL check in expandsid() and return an error when the SID extension is absent, so SID-based LDAPU1 mapping rules fail cleanly instead of dereferencing NULL. diff diff --git a/src/lib/certmap/ssscertmap.c b/src/lib/certmap/ssscertmap.c — a/src/lib/certmap/ssscertmap.c +++ b/src/lib/certmap/ssscertmap.c @@ -580,6 +580,11 @@ static int expandsid(struct ssscertmapctx ctx, const char attrname, char exp; char sep; + if (sid == NULL) { + CMDEBUG(ctx, "SID extension is missing."); + return ENOENT; + } + if (attrname == NULL) { exp = tallocstrdup(ctx, sid); } else if (strcasecmp(attrname, "rid") == 0) { ------ This report was generated using AI technology. Always review AI-generated content prior to use
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Until a fix is shipped, avoid LDAPU1 certmap rules that expand {sid} or {sid.rid}.
SSSD certificate mapping LDAPU1 certmap rules using {sid} or {sid.rid} = disabled - Configuration
If SID-based mapping is required, reject certificates missing Microsoft SID extension OID 1.3.6.1.4.1.311.25.2.
SSSD certificate mapping SID extension requirement = required
Event History
Frequently Asked Questions
Which deployments are exposed to this crash?
Affected deployments use SSSD certificate mapping with an LDAPU1 maprule that expands either {sid} or {sid.rid}. The affected component identified is sssd-2.12.0-1.el10.
What must an attacker provide to trigger the issue?
An attacker must be able to send a syntactically valid certificate through the affected certificate-mapping path. That certificate must omit the Microsoft SID extension OID 1.3.6.1.4.1.311.25.2.
Is the default configuration known to be affected?
The available information only identifies configurations with an LDAPU1 maprule using {sid} or {sid.rid}. It does not establish that default SSSD configurations enable such a rule.
What is the known impact?
The available evidence supports denial of service through a crash in the SSSD certificate-mapping path when certificate input is attacker-controlled. Broader impact has not been established.
Is a released fix available?
No released package fix has been established in the provided information, although a proposed patch is referenced.