Source: sssd Version: 2.13.1-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for sssd. CVE-2026-90463[0]: | A flaw was found in the sssd NSS responder. This input validation | vulnerability allows a local attacker, by sending specially crafted | service lookup requests to the NSS responder's UNIX socket, to cause | an out-of-bounds read. This out-of-bounds read may lead to a denial | of service (DoS) by crashing the NSS responder process. While | unprivileged local clients can typically reach the socket, there is | no evidence of privilege escalation or reliable data disclosure. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90463 https://www.cve.org/CVERecord?id=CVE-2026-90463 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2479268 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

