Beveiligingsadvies

CVE-2026-90463

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-14 15:21:01
Laatst bijgewerkt 2026-09-14 17:02:03
Toegewezen door redhat
CVSS-score 4.0
Status PUBLISHED

Beschrijving

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.