GPU VulnDB

Database/Kernel, userspace & hypervisor

SSSD autofs responder: invalid packet length triggers integer underflow and out-of-bounds read, crashing the responder

CVSS 5.5CVE-2026-104037Kernel, userspace & hypervisorcurated

Impact

A crafted request with an invalid packet length sent to the autofs responder's UNIX socket underflows an integer during parsing and causes an out-of-bounds read that crashes the responder process. Where automount maps come from SSSD - the normal arrangement for HPC and GPU clusters that mount shared home directories and dataset volumes on demand - a dead responder means new automount lookups stop resolving, so jobs that touch a path not already mounted fail. Red Hat scores this as availability-only; there is no indication of information disclosure or code execution. Note that this is one of several distinct autofs responder flaws Red Hat disclosed together; each has its own mechanism and its own bug report.

Who can reach it

Any local unprivileged user on the node that can write to the SSSD autofs responder UNIX socket. Local access only, no special privileges.

What to do

Install the fixed sssd packages from your distribution and restart sssd, which brings the autofs responder back; the record does not name a fixed version, so take it from the Red Hat advisory. No node reboot or GPU drain required. If patches are not yet available and the node does not need SSSD-provided automount maps, disabling the autofs responder removes the exposed socket entirely.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.