REDHAT-BUG-2479178: Use After Free

Published May 18, 2026
·
Updated

AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: Use-After-Free in KCM TGT Renewal (authdata->ccname lifetime mismatch): a deferred KCM renewal callback retains a shallow pointer to cc->name after the timer's temporary talloc context is freed, resulting in a local use-after-free read with likely KCM responder denial-of-service impact in affected renewal deployments. Requirements to exploit: An authenticated local user on a host using the KCM responder, with a renewable TGT stored in KCM. Reachability depends on builds with KCM renewal support and deployments configured with db = secdb and tgtrenewal = true; the user then waits for the normal renewal window. Component affected: sssd-2.12.0-1.el10, src/responder/kcm/kcmrenew.c, KCM TGT renewal path in kcmcredschecktimes() with deferred use in kcmrenewtgt() / kcmchildreqsetup(). Version affected: sssd-2.12.0-1.el10; reachability depends on builds with KCM renewal support and deployments using the KCM secdb backend with tgtrenewal = true Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H - 4.4 (MEDIUM) AV:L - Exploitation requires local access to a host using the affected KCM responder. AC:H - The vulnerable path is gated by non-default renewal configuration, the secdb backend, and renewal timing before the dangling pointer is consumed. PR:L - A regular authenticated local user with access to KCM and a renewable TGT can reach the path in an affected deployment. UI:N - No separate victim interaction is required once the vulnerable configuration is in place. S:U - The impact is confined to the KCM responder's own security scope. C:N - The available evidence does not establish confidentiality impact. I:N - The available evidence does not establish integrity impact. A:H - The demonstrated consequence is service crash or instability in the KCM responder, resulting in denial of service for affected KCM operations. Impact: Moderate. This issue can allow an authenticated local user to cause an availability impact in the KCM responder, but the affected renewal path is disabled by default and appears effectively limited to the secdb backend. No reliable confidentiality, integrity, or privilege-escalation impact is established from the available evidence. Under Red Hat's severity guidance, this is more appropriately Moderate than Important because it is a real denial-of-service issue in an opt-in, less easily exploited configuration rather than an easily reached default-path compromise. Embargo: no Reason: The currently supported impact is local denial of service in a configuration-gated feature path, and exposure can be reduced immediately by leaving tgtrenewal disabled or disabling renewal where it is enabled. This does not appear to warrant embargo. Acknowledgement: Aisle Research Vulnerability Details: In the KCM TGT renewal path, the renewal context stores a shallow pointer to the credential cache name, but the source object is tied to a temporary talloc context that is later freed before the deferred callback uses the pointer: c authdata->ccname = cc->name; ... tallocfree(tmpctx); ... krreq->ccname = tallocasprintf(krreq, "KCM:%s", authdata->ccname); authdata is queued to a deferred immediate callback, so its lifetime extends beyond the timer handler. The credential caches being iterated originate from a list allocated under tmpctx, which is freed after renewal scheduling completes. When the deferred path reaches kcmchildreqsetup(), authdata->ccname can already point to released memory. This is consistent with a CWE-416 use-after-free read and a CWE-664 lifetime management issue. The available material supports denial of service in the KCM responder; it does not establish reliable confidentiality, integrity, or code-execution impact. Steps to reproduce: 1. Build sssd-2.12.0-1.el10 with KCM renewal support enabled. 2. Configure the KCM responder to use db = secdb and tgtrenewal = true. A short renewal interval makes the issue easier to observe. 3. Restart sssd-kcm. 4. As an unprivileged local user, acquire a renewable TGT in KCM, for example by using KRB5CCNAME=KCM:.... 5. Wait until the renewal window is reached so the timer-driven renewal path executes. 6. Let the renewal timer schedule kcmrenewtgt, then allow the timer handler to finish and free tmpctx. 7. Run under ASan or Valgrind and observe an invalid read or use-after-free report when kcmchildreqsetup() formats KCM:%s with authdata->ccname. Mitigation: If KCM ticket renewal is not required, keep tgtrenewal = false, which avoids the affected path. On systems currently using KCM renewal, disabling the renewal feature until a fixed build is available reduces exposure. Proposed Fix: Deep-copy cc->name into authdata before scheduling the deferred callback, and fail cleanly if that allocation cannot be made. diff diff --git a/src/responder/kcm/kcmrenew.c b/src/responder/kcm/kcmrenew.c @@ -579,11 +579,16 @@ static errnot kcmcredschecktimes(TALLOCCTX memctx, authdata->krb5ctx = renewtgtctx->krb5ctx; authdata->upn = tallocstrdup(authdata, clientname); authdata->uid = cc->owner.uid; authdata->gid = cc->owner.gid; authdata->ccname = cc->name; + authdata->ccname = tallocstrdup(authdata, cc->name); if (authdata->upn == NULL) { ret = ENOMEM; DEBUG(SSSDBGCRITFAILURE, "Unable to allocate authdata->upn for renewals\n"); goto done; } + if (authdata->ccname == NULL) { + ret = ENOMEM; + DEBUG(SSSDBGCRITFAILURE, "Unable to allocate authdata->ccname for renewals\n"); + goto done; + }

------ This report was generated using AI technology. Always review AI-generated content prior to use

Affected Software

1 affected component
redhat/sssd=2.12.0-1.el10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable KCM TGT renewal by setting tgt_renewal = false, especially when renewal is not required or until a fixed build is available.

    SSSD KCM responder tgt_renewal = false
  2. Operational

    Restart sssd-kcm after disabling KCM TGT renewal.

Event History

May 18, 2026
Data Sourced
via Red Hat·03:57 AM
DescriptionSeverityAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203