Bug#1143600: sssd: CVE-2026-68742 CVE-2026-68744
Salvatore Bonaccorso <[email protected]> Tue, 04 Aug 2026 19:47:41 +0200
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Source: sssd Version: 2.12.0-4 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for sssd. There is litte information available, can you check the upstream status please and report back? Are they known, are they already fixed? CVE-2026-68742[0]: | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function | in the NSS responder does not validate the addrlen field against the | remaining packet body size. A local attacker can exploit this via a | crafted GETHOSTBYADDR request to the NSS responder socket, causing | an out-of-bounds read and process crash, resulting in a denial of | service. CVE-2026-68744[1]: | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() | function in the NSS responder pre-allocates reply space for all | group entries but does not shrink the packet when groups are | skipped, causing uninitialized heap bytes to be transmitted to the | client. A local attacker can exploit this to disclose cached | directory data and heap layout information from the sssd_nss | process. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-68742 https://www.cve.org/CVERecord?id=CVE-2026-68742 [1] https://security-tracker.debian.org/tracker/CVE-2026-68744 https://www.cve.org/CVERecord?id=CVE-2026-68744 Regards, Salvatore