Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Tue, 04 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | sssd: sssd: PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1 | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
|
Mon, 03 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sssd
Sssd sssd |
|
| Vendors & Products |
Sssd
Sssd sssd |
Mon, 03 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | |
| Title | sssd: sssd: PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1 | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-04T19:10:51.243Z
Reserved: 2026-07-31T12:44:34.409Z
Link: CVE-2026-68743
Updated: 2026-08-04T19:10:19.852Z
Status : Awaiting Analysis
Published: 2026-08-04T19:16:53.467
Modified: 2026-08-06T15:37:22.093
Link: CVE-2026-68743
OpenCVE Enrichment
Updated: 2026-08-04T09:15:03Z