Database/Kernel, userspace & hypervisor
SSSD: race between autofs enumeration and map invalidation leaks memory until the responder dies
Impact
A local user who can talk to the SSSD autofs responder can send concurrent map enumeration and invalidation requests, leaking memory until the autofs service degrades or crashes. On compute and login nodes that mount home directories or shared scratch via autofs and resolve identity through SSSD, losing the autofs responder means new automount lookups stop resolving - jobs that touch a not-yet-mounted path fail even though the node is otherwise healthy. Confidentiality and integrity are unaffected; the record scores this availability-only with high attack complexity, reflecting that it is a race the attacker has to win repeatedly. Red Hat lists RHEL 6 through 10 and OpenShift Container Platform 4 as affected.
Who can reach it
Local user on the node with the ability to issue autofs requests to SSSD; low privileges are enough, no special device or group membership. Not reachable from the network.
What to do
Install the SSSD update from your distribution and restart sssd (the autofs responder restarts with it); automounts re-resolve afterwards. No node reboot or drain is required. The record does not name fixed package versions - check the Red Hat CVE page for the build that applies to your release.
References
Related entries
- Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failureCVE-2026-43097 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/vfio/mdev): If creating an mdev type's sysfs entries partially fails, the parent still registersCVE-2023-52570 · Linux kernel (drivers/vfio/mdev)Medium
- util-linux (wall): WallEscape: escape-sequence injection via wall(1)CVE-2024-28085 · util-linux (wall)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/endpoint/functions): The NTB endpoint function drivers never checked whether their workqueueCVE-2025-71313 · Linux kernel (drivers/pci/endpoint/functions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.