Database/Kernel, userspace & hypervisor
SSSD autofs responder: invalid packet length triggers integer underflow and out-of-bounds read, crashing the responder
Impact
A crafted request with an invalid packet length sent to the autofs responder's UNIX socket underflows an integer during parsing and causes an out-of-bounds read that crashes the responder process. Where automount maps come from SSSD - the normal arrangement for HPC and GPU clusters that mount shared home directories and dataset volumes on demand - a dead responder means new automount lookups stop resolving, so jobs that touch a path not already mounted fail. Red Hat scores this as availability-only; there is no indication of information disclosure or code execution. Note that this is one of several distinct autofs responder flaws Red Hat disclosed together; each has its own mechanism and its own bug report.
Who can reach it
Any local unprivileged user on the node that can write to the SSSD autofs responder UNIX socket. Local access only, no special privileges.
What to do
Install the fixed sssd packages from your distribution and restart sssd, which brings the autofs responder back; the record does not name a fixed version, so take it from the Red Hat advisory. No node reboot or GPU drain required. If patches are not yet available and the node does not need SSSD-provided automount maps, disabling the autofs responder removes the exposed socket entirely.
References
Related entries
- systemd-oomd: unprivileged local users can kill arbitrary processes via unvalidated IPC pathCVE-2026-15059 · systemd-oomd (IPC API cgroup path validation)Medium
- Linux i915 GPU kernel driver (submission backend setup): i915 dereferences the submission backend before checkingCVE-2026-31540 · Linux i915 GPU kernel driver (submission backend setup)Medium
- Linux kernel Intel uncore PMU: die ID lookup bugs trip a warning and skip PMON unitsCVE-2026-43344 · Linux kernel perf/x86/intel/uncore (die ID init and lookup on Intel SPR/EMR)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-43444 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/pci): A failed mmap of peer-to-peer DMA memory leaks the pgmap reference it took, and the leak isCVE-2026-45880 · Linux kernel (drivers/pci)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingCVE-2026-46229 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.