LOWVulnerability

CVE-2026-68744

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.

Properties

severity
LOW
score
3.3
cve_id
CVE-2026-68744
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-04T06:16:30.490
last_modified
2026-08-18T16:37:05.247

Related Entities (8)

AFFECTS_PRODUCT (6)

[Product]
[Product]
[Product]
[Product]
[Product]
[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of Uninitialized Resource

Explore deeper with Ninja Signal's threat intelligence graph