Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.18% | — | Sssd-kcmAI | 6/10/2026 | 6/10/2026 | A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the… | |
| Recibida | Media (6.2) | 0.13% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authentication is enabled, pre-authentication requests retain state in memory without being cleared or timed out. A local attacker can repeatedly initiate authentication flows without completing them, causing unbounded memory… | |
| Recibida | Media (4.7) | 0.10% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. By repeatedly sending concurrent map enumeration and invalidation requests, an attacker can cause memory to leak, leading… | |
| Recibida | Media (6.8) | 0.28% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access… | |
| Recibida | Media (5.3) | 0.11% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information… | |
| Pendiente de análisis | Media (4.7) | 0.14% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an… | |
| En análisis | Media (6.2) | 0.12% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process… | |
| En análisis | Media (5.5) | 0.11% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS) responder. Because the negative cache does not limit the total number of stored entries and only removes expired records when an existing key is rechecked, the cache can… | |
| En análisis | Media (4.4) | 0.10% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request,… | |
| En análisis | Media (4.7) | 0.10% | — | SssdAI | 6/10/2026 | 6/10/2026 | A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon… | |
| En análisis | Media (6.8) | 0.31% | — | Redhat SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an… | |
| En análisis | Media (5.9) | 0.22% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it,… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS). | |
| En análisis | Media (5.8) | 0.09% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized cached entries,… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are… | |
| En análisis | Media (4.7) | 0.09% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger… | |
| En análisis | Media (5.4) | 0.19% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookups to backend directory providers, leading to a Denial of Service (DoS) from… | |
| En análisis | Media (5.5) | 0.10% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid… | |
| En análisis | Media (5.5) | 0.12% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting… | |
| En análisis | Baja (3.3) | 0.10% | — | SssdAI | 5/10/2026 | 6/10/2026 | A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to… | |
| Analizada | Media (5.4) | 0.21% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/9/2026 | 7/10/2026 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued… | |
| Pendiente de análisis | Media (4) | 0.16% | — | SssdAI | 14/9/2026 | 16/9/2026 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability… |