Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder (src/responder/nss/nss_protocol.c) extracts a 32-bit addrlen value from the client request but only validates that the body is at least 8 bytes, without checking that addrlen fits within the remaining packet body. This unvalidated length is passed through to talloc_memdup() in cache_req_data_create(), which copies addrlen bytes from the small request buffer, causing a heap-buffer-overflow read. A local attacker can trigger this by connecting to the world-writable NSS responder socket (/var/lib/sss/pipes/nss) and sending a SSS_NSS_GETHOSTBYADDR (0x0053) request with a large addrlen value and a valid address family payload so that inet_ntop() succeeds. Successful exploitation crashes the sssd_nss responder, causing a denial of service for NSS name resolution. Reported via PSIRTSUPT-20553 by BreachX Zero Day Labs.
Upstream PR: https://github.com/SSSD/sssd/pull/9039
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.
Fixed upstream by https://github.com/SSSD/sssd/commit/2839e8ccffebbb6bd605047b012eaa5fdb56b9d3