VendorsFedora Projectsssdany version
Vulnerabilities

Fedora Project Fedora SSSD any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
Published 2018-07-27 · Modified
8.8EPSS 0.015
CVE-2022-4254
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Published 2023-02-01 · Modified
8.8EPSS 0.010
CVE-2018-10852
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
Published 2018-06-26 · Modified
7.5EPSS 0.015
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2026-68743
Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1
Published 2026-08-04 · Analyzed
7.1EPSS 0.001
CVE-2026-12610
Sssd: use-after-free crash in sssd' 'sssd_pam' process
Published 2026-06-30 · Undergoing Analysis
6.4EPSS 0.001
CVE-2018-16838
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
Published 2019-03-25 · Modified
5.5EPSS 0.011
CVE-2018-16883
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
Published 2018-12-19 · Modified
5.5EPSS 0.004
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2019-3811
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
Published 2019-01-15 · Modified
5.2EPSS 0.007
CVE-2013-0220
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
Published 2013-02-24 · Modified
5.0EPSS 0.033
CVE-2010-0014
System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.
Published 2010-01-14 · Modified
3.7EPSS 0.007
CVE-2013-0219
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
Published 2013-02-24 · Modified
3.7EPSS 0.004
CVE-2026-68744
Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
Published 2026-08-04 · Analyzed
3.3EPSS 0.001