REDHAT-BUG-2509761: Low severity sssd vulnerability

Published Jul 31, 2026
·
Updated

A flaw was found in SSSD. The sssnssprotocolfillinitgr() function in the NSS responder (src/responder/nss/nssprotocolgrent.c) pre-allocates the reply packet for all group entries using ssspacketgrow() but does not shrink the packet when groups are skipped (non-POSIX, incomplete, or filtered groups). ssspacketgrow() uses tallocreallocsize(), which does not zero-fill newly allocated memory. The trailing unwritten bytes therefore contain uninitialized heap data from the sssdnss process and are transmitted to the client at the grown packet length. A local attacker can exploit this by sending SSSNSSINITGR (0x0026) requests to the world-writable NSS responder socket (/var/lib/sss/pipes/nss), receiving uninitialized heap content in the reply tail. Through heap grooming (for example, a preceding getpwnam query), the leak can disclose other users' cached directory records and process heap pointers. The leaked data is limited to the sssdnss heap (directory-level information); credentials reside in separate sssdpam and sssdbe processes. Reported via PSIRTSUPT-20553 by BreachX Zero Day Labs.

Affected Software

1 affected component
sssd

Event History

Jul 31, 2026
Data Sourced
via Red Hat·12:31 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2509761?

The severity of REDHAT-BUG-2509761 is classified as low.

2

What impact does REDHAT-BUG-2509761 have on SSSD?

REDHAT-BUG-2509761 can lead to inefficient memory usage by not shrinking the packet when certain groups are skipped.

3

How do I mitigate the effects of REDHAT-BUG-2509761?

To mitigate REDHAT-BUG-2509761, you should ensure that all group entries processed by SSSD are complete and POSIX compliant.

4

What software is affected by REDHAT-BUG-2509761?

The software affected by REDHAT-BUG-2509761 is SSSD.

5

When was REDHAT-BUG-2509761 published?

REDHAT-BUG-2509761 was published on July 31, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203