Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68743— Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1

CVSS 5.5 · Medium
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-68743

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat OpenShift Container Platform 4-cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-68743

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68743

登录查看更多情报信息。

Vendor Advisories for CVE-2026-68743 (1)

Other References for CVE-2026-68743 (1)

Same Patch Batch · Red Hat · 2026-08-04 · 8 CVEs total

CVE-2026-421697.3 HIGHGimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c
CVE-2026-703686.5 MEDIUMStunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
CVE-2026-703675.4 MEDIUMStunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified
CVE-2026-176144.4 MEDIUMWildfly-core: path traversal on wildfly domain controller
CVE-2026-185693.7 LOWKeycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logo
CVE-2026-687443.3 LOWSssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
CVE-2026-187392.5 LOWPopt-devel: popt-static: off-by-one in poptstuffargs

IV. Related Vulnerabilities

V. Comments for CVE-2026-68743

No comments yet


Leave a comment