A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by… (CVE-2026-104035)
Description
A vulnerability in SSSD's Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining persistent connections and repeatedly storing and destroying credentials. This leads to continuous memory consumption growth due to failure to release cached objects, eventually exhausting memory and making the service unresponsive. The issue affects multiple specific versions of SSSD. The CVSS score is 5.5, indicating a medium severity impact focused on availability.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104035 is a vulnerability in the SSSD Kerberos Credential Manager (KCM) responder where a local user can cause a Denial of Service by maintaining a persistent connection and repeatedly storing and destroying credentials. The service does not release cached objects from memory when credentials are removed, causing memory consumption to grow continuously until available memory is exhausted and the service becomes unresponsive. This affects numerous specific versions of SSSD as listed. The CVSS 3.1 vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local attack vector, low complexity, low privileges required, no user interaction, unchanged scope, no confidentiality or integrity impact, but high impact on availability.
Potential Impact
The vulnerability allows a local user to cause a Denial of Service by exhausting memory resources of the SSSD service through repeated credential operations. This results in the service becoming unresponsive, impacting availability. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, limit local user access to trusted users only to reduce risk of exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-104035
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fcc2cdf04f65639c4be
Added to database: 10/08/2026, 21:49:00 UTC
Last enriched: 10/08/2026, 22:17:26 UTC
Last updated: 10/09/2026, 01:48:07 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.