A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by… (CVE-2026-104043)
Description
A local attacker with access to the Name Service Switch (NSS) responder UNIX socket in SSSD can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This causes an out-of-bounds memory read during packet parsing, crashing the responder process and resulting in a Denial of Service (DoS). The vulnerability affects multiple specific versions of SSSD. The CVSS score is 5.5, indicating a medium severity level.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104043 is a vulnerability in SSSD where a local attacker with access to the NSS responder UNIX socket can cause an integer underflow by sending a specially crafted request with an undersized packet header. This leads to an out-of-bounds memory read during packet parsing, crashing the responder process and causing a Denial of Service. The vulnerability affects numerous specific versions of SSSD as listed. There is no information provided about available patches or vendor advisories in the input data.
Potential Impact
The vulnerability results in a Denial of Service (DoS) by crashing the NSS responder process due to an out-of-bounds memory read triggered by an integer underflow. There is no indication of confidentiality or integrity impact. The attack requires local access to the NSS responder UNIX socket.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local access to the NSS responder UNIX socket to trusted users only to reduce the risk of exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-104043
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fcb2cdf04f65639c4b4
Added to database: 10/08/2026, 21:48:59 UTC
Last enriched: 10/08/2026, 22:15:06 UTC
Last updated: 10/09/2026, 04:48:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.