Database/Kernel, userspace & hypervisor
SSSD NFS idmap plugin: oversized cached entry copied past the destination buffer, crashing ID mapping
Impact
When the SSSD NFS idmap plugin retrieves a cached user or group name it detects that the entry exceeds the destination buffer but copies anyway, producing an out-of-bounds write. Red Hat describes the primary outcome as a denial of service by crashing the identity mapping service, with possible corruption of adjacent process memory. On a GPU or HPC node that mounts NFSv4 home directories and datasets, losing ID mapping means UIDs and GIDs resolve to nobody, so running jobs lose access to their data and new ones fail to start - an availability problem that looks like a storage outage. The memory-corruption half is unquantified in this record; treat it as a crash bug unless Red Hat says more.
Who can reach it
A local user on the node who can request identity lookups that resolve to oversized cached entries. Authentication as an ordinary local user is required, and Red Hat rates attack complexity high because the attacker must get an oversized entry into the cache.
What to do
Install the fixed sssd packages from your distribution and restart sssd together with the NFS ID mapping consumers; the record does not name a fixed version, so take it from the Red Hat advisory. No reboot or GPU node drain is needed, but expect a brief ID-mapping gap on restart, so do it on nodes that are idle or tolerate it. Applies to RHEL 6 through 10 and OpenShift Container Platform 4 node images, which update by rolling new nodes in.
References
Related entries
- Intel CPU (L1TF / Foreshadow-NG): L1 Terminal Fault: a guest reads any data present in the L1 data cache, includingCVE-2018-3646 · Intel CPU (L1TF / Foreshadow-NG)Medium
- Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry paths: The kernel's syscall/interrupt entry pathCVE-2019-1125 · Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry pathsMedium
- AMD CPU (Branch Type Confusion): Non-Retbleed branch type confusion - speculative cross-domain leakCVE-2022-23825 · AMD CPU (Branch Type Confusion)Medium
- AMD CPU (Retbleed): Retbleed: arbitrary speculative code execution via return instructionsCVE-2022-29900 · AMD CPU (Retbleed)Medium
- Intel CPU (Retbleed): Retbleed on Intel - speculative execution of return instructions leaks across privilege boundariesCVE-2022-29901 · Intel CPU (Retbleed)Medium
- AMD CPU (Inception / SRSO): Inception: Speculative Return Stack OverflowCVE-2023-20569 · AMD CPU (Inception / SRSO)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.