CVE-2026-68744 - Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
CVE ID :CVE-2026-68744
Published : Aug. 4, 2026, 6:16 a.m. | 37 minutes ago
Description :A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 4, 2026, 6:16 a.m. | 37 minutes ago
Description :A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...