Security Advisory

CVE-2026-90463

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-14 15:21:01
Last updated 2026-09-14 17:02:03
Assigner redhat
CVSS score 4.0
State PUBLISHED

Description

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.