Database/Kernel, userspace & hypervisor
SSSD autofs responder: memory from successful requests is held until disconnect, allowing local memory exhaustion
Impact
With the autofs responder enabled, memory allocated while handling successful requests is not freed until the client connection closes. A local user who holds one connection open and keeps submitting valid requests drives SSSD's memory use up until the process or the node runs out of memory. This is a resource-exhaustion denial of service rather than a parsing bug, so it needs no malformed input and nothing to go wrong - just a loop. On a shared GPU node, memory pressure from the identity daemon can take down co-resident workloads too, not only automount, and recovering may require restarting SSSD or the node.
Who can reach it
Any local unprivileged user on the node that can connect to the SSSD autofs responder UNIX socket and issue ordinary, valid requests. Local access only.
What to do
Install the fixed sssd packages and restart sssd to reclaim the leaked memory; the record does not name a fixed version, so take it from the Red Hat advisory. Daemon restart is enough - no node reboot - though a node already pushed into OOM may need more. If the node does not consume SSSD-provided automount maps, disabling the autofs responder removes the exposure.
References
Related entries
- SSSD autofs responder: missing authorization lets any local user force repeated automount cache invalidationCVE-2026-104032 · SSSD autofs responder (master map update authorization)Medium
- SSSD autofs responder: invalid packet length triggers integer underflow and out-of-bounds read, crashing the responderCVE-2026-104037 · SSSD autofs responder (request length parsing)Medium
- systemd-oomd: unprivileged local users can kill arbitrary processes via unvalidated IPC pathCVE-2026-15059 · systemd-oomd (IPC API cgroup path validation)Medium
- Linux i915 GPU kernel driver (submission backend setup): i915 dereferences the submission backend before checkingCVE-2026-31540 · Linux i915 GPU kernel driver (submission backend setup)Medium
- Linux kernel Intel uncore PMU: die ID lookup bugs trip a warning and skip PMON unitsCVE-2026-43344 · Linux kernel perf/x86/intel/uncore (die ID init and lookup on Intel SPR/EMR)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-43444 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.