Database/Kernel, userspace & hypervisor
SSSD autofs responder: missing authorization lets any local user force repeated automount cache invalidation
Impact
The autofs responder does not check authorization on master automount map update requests, so an unprivileged local user can ask for them repeatedly. Each request invalidates the global cache and forces fresh lookups against the backend directory provider. The result is degraded or unavailable automount on the node plus amplified load on shared LDAP or Active Directory infrastructure - so the damage is not confined to the node the attacker sits on, which matters on a cluster where hundreds of nodes share one identity backend. This is an authorization gap, not a memory-safety bug: availability impact only, no disclosure or code execution.
Who can reach it
Any local unprivileged user on the node that can reach the SSSD autofs responder socket. No privileges beyond a local account.
What to do
Install the fixed sssd packages and restart sssd; the record does not name a fixed version, so take it from the Red Hat advisory. Daemon restart only, no node reboot or GPU drain. Where SSSD-sourced automount maps are not needed, disabling the autofs responder removes the request path; rate limiting on the identity backend reduces the amplification but does not fix the node-local effect.
References
Related entries
- SSSD autofs responder: invalid packet length triggers integer underflow and out-of-bounds read, crashing the responderCVE-2026-104037 · SSSD autofs responder (request length parsing)Medium
- systemd-oomd: unprivileged local users can kill arbitrary processes via unvalidated IPC pathCVE-2026-15059 · systemd-oomd (IPC API cgroup path validation)Medium
- Linux i915 GPU kernel driver (submission backend setup): i915 dereferences the submission backend before checkingCVE-2026-31540 · Linux i915 GPU kernel driver (submission backend setup)Medium
- Linux kernel Intel uncore PMU: die ID lookup bugs trip a warning and skip PMON unitsCVE-2026-43344 · Linux kernel perf/x86/intel/uncore (die ID init and lookup on Intel SPR/EMR)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-43444 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/pci): A failed mmap of peer-to-peer DMA memory leaks the pgmap reference it took, and the leak isCVE-2026-45880 · Linux kernel (drivers/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.