Ad

CVE-2026-90995

MEDIUM CVSS 3.1: 5,5 EPSS 0.11%
Обновлено 14 сентября 2026
Red Hat
Параметр Значение
CVSS 5,5 (MEDIUM)
Тип уязвимости CWE-476 (Разыменование нулевого указателя)
Поставщик Red Hat
Публичный эксплойт Нет

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur.

This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

Характеристики атаки

Способ атаки
Локальный
Нужен локальный доступ
Сложность
Низкая
Легко эксплуатировать
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Нет
Нет модификации данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1

Уязвимые продукты

red hat:red hat enterprise linux 6 red hat:red hat openshift container platform 4 red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 8 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux 9