A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is… (CVE-2026-104031)
Description
A memory management flaw exists in SSSD when the autofs responder service is enabled. Memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this by maintaining an open connection and repeatedly submitting valid requests, causing memory exhaustion and a Denial of Service (DoS). The vulnerability has a medium severity with a CVSS score of 5.5.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104031 describes a vulnerability in SSSD where, if the autofs responder service is enabled, memory allocated during successful request processing is retained until the client connection closes. This allows a local attacker to cause memory exhaustion by keeping a connection open and sending repeated valid requests, resulting in a Denial of Service condition. The vulnerability affects multiple specific versions of SSSD as listed, and no known exploits are reported in the wild.
Potential Impact
The impact is a Denial of Service (DoS) caused by memory exhaustion on the affected system. There is no impact on confidentiality or integrity. The attacker must have local access and the ability to maintain an open connection to exploit this flaw.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, limit local access to trusted users and monitor for unusual resource consumption related to SSSD autofs responder service connections.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-104031
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fcc2cdf04f65639c4c2
Added to database: 10/08/2026, 21:49:00 UTC
Last enriched: 10/08/2026, 22:18:43 UTC
Last updated: 10/09/2026, 04:48:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.