CVE-2026-68744

LOW CVSS 3.1: 3.3 EPSS 0.10%
Updated Aug 06, 2026
Red Hat
Parameter Value
CVSS 3.3 (LOW)
Type CWE-908 (Use of Uninitialized Resource)
Vendor Red Hat
Public PoC No

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 6 red hat:red hat openshift container platform 4 red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 8 red hat:red hat enterprise linux 10