A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS)… (CVE-2026-104041)
Description
A vulnerability in SSSD allows an unprivileged local user to cause memory exhaustion by repeatedly requesting lookups for nonexistent entries through the Name Service Switch (NSS) responder. The negative cache does not limit the total number of stored entries and only removes expired records when an existing key is rechecked, which can lead to unbounded cache growth. This can result in a Denial of Service (DoS) as the responder becomes unresponsive or terminates. The issue affects multiple specific versions of SSSD. The CVSS score is 5.5, indicating a medium severity level.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104041 is a vulnerability in SSSD where the negative cache used by the NSS responder does not limit the total number of stored entries and only removes expired records upon rechecking existing keys. An unprivileged local user can exploit this by repeatedly requesting lookups for nonexistent entries, causing the cache to grow without bound. This behavior can exhaust memory resources, leading to a Denial of Service (DoS) as the NSS responder becomes unresponsive or terminates. The vulnerability affects numerous specific SSSD versions as enumerated in the affectedVersions list. The CVSS 3.1 base score is 5.5 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Potential Impact
The vulnerability allows an unprivileged local user to cause memory exhaustion on the system running SSSD by abusing the negative cache mechanism in the NSS responder. This results in a Denial of Service (DoS) condition where the responder becomes unresponsive or terminates, potentially disrupting name service lookups and related system functions. There is no impact on confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, limit access to systems running affected SSSD versions to trusted users only to reduce risk. Monitor for unusual local user activity involving repeated lookups of nonexistent entries. No vendor advisory or patch links are provided in the current data.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-104041
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fcb2cdf04f65639c4b6
Added to database: 10/08/2026, 21:48:59 UTC
Last enriched: 10/08/2026, 22:15:41 UTC
Last updated: 10/09/2026, 04:48:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.