CVE-2026-104039: medium-severity vulnerability in Red Hat Enterprise Linux 10
Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.7epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer. An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat OpenShift Container Platform 4Related CVEs — Red Hat Enterprise Linux 10
In the same product, most dangerous first.
CVE-2023-4911HIGHGlibc: buffer overflow in ld.so leading to privilege escalationEPSS 63.8%KEVCVE-2024-6387HIGHOpenssh: regresshion - race condition in ssh allows rce/dosEPSS 99.5%CVE-2023-46847HIGHSquid: denial of service in http digest authenticationEPSS 88.4%CVE-2024-3094CRITICALXz: malicious code in distributed sourceEPSS 86.0%CVE-2024-12084CRITICALRsync: heap buffer overflow in rsync due to improper checksum length handlingEPSS 72.1%CVE-2023-1183MEDIUMArbitrary file writeEPSS 64.6%