Skip to content
Red HatCVE-2026-68744

Red Hat SSSD: uninitialized resource

Low3.3CVE-2026-68744 · Published Aug 4, 2026 · updated Aug 31, 2026

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-908

More Red Hat advisories

All Red Hat
Advisory
Red Hat SSSD: out-of-bounds read
Medium5.5Aug 4
Red Hat Enterprise Linux 10: server-side request forgery
Medium5.4Aug 4
Red Hat Enterprise Linux 10: out-of-bounds read
Medium6.5Aug 4
Red Hat Build of Keycloak: improper signature check
Low3.7Aug 4
Red Hat popt: code execution
Low2.5Aug 4
Red Hat Enterprise Linux: heap buffer overflow
High7.3Aug 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.