REDHAT-BUG-2479418: Medium severity redhat/sssd vulnerability
AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: Local DoS in Autofs responder due to per-request autofscmdctx lifetime bug (and pinned enum references): successful autofs responder requests can retain per-request state until connection close, allowing local memory exhaustion when the autofs responder/socket is enabled and reachable. Requirements to exploit: A local actor must be able to reach the autofs responder/socket in an affected deployment, keep a client connection open, and send a large number of valid autofs requests that complete successfully. Component affected: sssd-2.12.0-1.el10 Autofs responder, primarily src/responder/autofs/autofssrvcmd.c (sssautofscmdsetautomntentdone, sssautofscmdgetautomntentdone, sssautofscmdgetautomntbynamedone) and src/responder/common/respondercmd.c (ssscmddone) Version affected: sssd-2.12.0-1.el10, when the autofs responder/socket is enabled and reachable by a local user Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - 5.5 (MEDIUM) AV:L - Exploitation requires local access to a reachable autofs responder/socket. AC:L - The issue can be triggered by repeatedly sending valid successful requests over one connection. PR:L - The attacker must be able to use the local autofs responder in an affected deployment; the available evidence does not establish anonymous reachability for all configurations. UI:N - No user interaction is required once the attacker can reach the responder. S:U - The impact remains within the SSSD responder's security scope. C:N - No confidentiality impact is shown by the available evidence. I:N - No integrity impact is shown by the available evidence. A:H - Repeated retained request contexts can exhaust responder memory and disrupt service. Impact: Moderate. This is an availability issue with a credible memory-exhaustion outcome, but the demonstrated attack is local and depends on the autofs responder/socket being enabled and reachable. Under Red Hat's severity guidance, that is better classified as Moderate than Important because the report does not establish remote reachability, privilege escalation, or broader system compromise. Embargo: no Reason: The demonstrated impact is local, availability-only, and configuration-dependent, and practical mitigation exists by disabling or restricting access to the autofs responder until a fix is shipped. Acknowledgement: Aisle Research Vulnerability Details: autofscmdctx is allocated per request as a child of the long-lived client connection context (cmdctx = talloczero(clictx, struct autofscmdctx);). In the async success path, the responder writes the reply and then finishes with ssscmddone(cmdctx->clictx, NULL): c sssautofscmdgetautomntentdone(struct teventreq req) { struct autofsenumctx enumctx; struct autofscmdctx cmdctx; errnot ret; cmdctx = teventreqcallbackdata(req, struct autofscmdctx); ret = autofssetentrecv(cmdctx, req, &enumctx); talloczfree(req); if (ret != EOK) { autofscmddone(cmdctx, ret); return; } ret = autofswritegetautomntentoutput(cmdctx->clictx, enumctx, cmdctx->cursor, cmdctx->maxentries); if (ret != EOK) { DEBUG(SSSDBGCRITFAILURE, "Unable to create reply packet " "[%d]: %s\n", ret, sssstrerror(ret)); autofscmddone(cmdctx, ret); return; } ssscmddone(cmdctx->clictx, NULL); } ssscmddone() only frees the explicit freectx argument: c void ssscmddone(struct clictx cctx, void freectx) { / now that the packet is in place, unlock queue making the event writable / TEVENTFDWRITEABLE(cctx->cfde);
/ free all request related data through the talloc hierarchy / tallocfree(freectx); } The same success-path pattern is present in sssautofscmdsetautomntentdone and sssautofscmdgetautomntbynamedone. By contrast, handled error paths use autofscmddone(cmdctx, ret), which frees cmdctx, so the retained lifetime appears limited to successful asynchronous completions. In the GETAUTOMNTENT path, autofssetentrecv(cmdctx, req, &enumctx) additionally does enumctx = tallocreference(memctx, state->enumctx);; because cmdctx is used as memctx, leaked request contexts can also retain that extra reference. Repeating successful requests over one long-lived connection can therefore grow responder memory until the connection is closed or the process is restarted. Steps to reproduce: 1. Run SSSD with the autofs responder enabled and ensure the autofs responder/socket is reachable in the target deployment. 2. Open one persistent client connection to the autofs responder. 3. Over that same connection, send a high volume of valid successful SETAUTOMNTENT, GETAUTOMNTENT, or GETAUTOMNTBYNAME requests. 4. Observe responder RSS or heap usage while the connection remains open. 5. Confirm that memory usage grows with request count and does not return to baseline until the connection is closed or the process is restarted. 6. Optionally apply the three-line patch below and repeat the same request pattern; the per-request accumulation should stop. Mitigation: If the autofs responder is not required, disable it. Otherwise, restrict access to the autofs responder/socket to trusted local clients only until a fixed package is available. Closing long-lived client connections or restarting the responder reclaims retained objects, but that is operational containment rather than a complete fix. Proposed Fix: Pass cmdctx instead of NULL to ssscmddone() in the three async success callbacks so the per-request context is released after successful completion. diff diff --git a/src/responder/autofs/autofssrvcmd.c b/src/responder/autofs/autofssrvcmd.c — a/src/responder/autofs/autofssrvcmd.c +++ b/src/responder/autofs/autofssrvcmd.c @@ -517,7 +517,7 @@ sssautofscmdsetautomntentdone(struct teventreq req) ssscmddone(cmdctx->clictx, NULL); + ssscmddone(cmdctx->clictx, cmdctx); @@ -727,7 +727,7 @@ sssautofscmdgetautomntentdone(struct teventreq req)
ssscmddone(cmdctx->clictx, NULL); + ssscmddone(cmdctx->clictx, cmdctx); @@ -927,7 +927,7 @@ sssautofscmdgetautomntbynamedone(struct teventreq req)
ssscmddone(cmdctx->clictx, NULL); + ssscmddone(cmdctx->clictx, cmdctx);
------ This report was generated using AI technology. Always review AI-generated content prior to use
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the autofs responder if it is not required.
SSSD autofs responder autofs responder/socket = disabled - Compensating control
Restrict access to the autofs responder/socket to trusted local clients until a fix is shipped.
- Operational
Close long-lived client connections to the autofs responder or restart the responder to reclaim retained request objects.