Database/Kernel, userspace & hypervisor
SSSD autofs responder: improper buffer offset during request parsing causes out-of-bounds read and crash
Impact
A crafted request to the autofs responder's UNIX socket makes the service miscalculate a buffer offset while parsing and read out of bounds, which can crash the responder. The practical effect on a cluster node whose automount maps come from SSSD is that on-demand mounts of shared home directories and dataset volumes stop resolving until SSSD is restarted, so jobs touching an unmounted path fail. Red Hat scores it 3.3 - the lowest of the autofs responder set - with availability impact only and no disclosure or execution. This is a separate flaw from the other autofs responder parsing bugs disclosed alongside it, with its own bug report and its own fix.
Who can reach it
Any local unprivileged user on the node that can write to the SSSD autofs responder UNIX socket. Local access only.
What to do
Install the fixed sssd packages and restart sssd; the record does not name a fixed version, so take it from the Red Hat advisory. Daemon restart only - no reboot, no GPU node drain. Disabling the autofs responder is an option on nodes that do not use SSSD-sourced automount maps.
References
Related entries
- OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingCVE-2026-73283 · OpenSSH sshd (authorized_keys restrict keyword vs tunnel forwarding)Low
- QEMU / KVM / Xen (VENOM): VENOM: out-of-bounds write in the virtual Floppy Disk ControllerCVE-2015-3456 · QEMU / KVM / Xen (VENOM)Low
- Xen (shadow paging): x86 shadow paging arbitrary pointer dereference - host crash or worseCVE-2022-42335 · Xen (shadow paging)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2022-50619 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2023-54144 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2023-54261 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.