Vulnerability record · CVE-2026-68744 · published 4 August 2026
CVE-2026-68744: Fedoraproject sssd use of uninitialized resource vulnerability
Fedoraproject · Sssd
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
Description
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-68744 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2509761 | Issue TrackingVendor Advisory |
Track CVE-2026-68744 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-68744), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.