#1143600 sssd: CVE-2026-68742 CVE-2026-68744

Package:
src:sssd
Source:
src:sssd
Submitter:
Salvatore Bonaccorso
Date:
2026-09-04 21:41:04 UTC
Severity:
normal
Tags:
#1143600#5
Date:
2026-08-04 17:47:41 UTC
From:
To:
Hi,

The following vulnerabilities were published for sssd.

There is litte information available, can you check the upstream
status please and report back? Are they known, are they already fixed?

CVE-2026-68742[0]:
| A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function
| in the NSS responder does not validate the addrlen field against the
| remaining packet body size. A local attacker can exploit this via a
| crafted GETHOSTBYADDR request to the NSS responder socket, causing
| an out-of-bounds read and process crash, resulting in a denial of
| service.


CVE-2026-68744[1]:
| A flaw was found in SSSD. The sss_nss_protocol_fill_initgr()
| function in the NSS responder pre-allocates reply space for all
| group entries but does not shrink the packet when groups are
| skipped, causing uninitialized heap bytes to be transmitted to the
| client. A local attacker can exploit this to disclose cached
| directory data and heap layout information from the sssd_nss
| process.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-68742
https://www.cve.org/CVERecord?id=CVE-2026-68742
[1] https://security-tracker.debian.org/tracker/CVE-2026-68744
https://www.cve.org/CVERecord?id=CVE-2026-68744

Regards,
Salvatore

#1143600#10
Date:
2026-09-04 05:38:48 UTC
From:
To:
Hi,

I would like to do an NMU to fix this/these bug(s). Patches exist in
upstream github repo. I'll pick those patches.

CVE-2026-68744: https://github.com/SSSD/sssd/pull/9217
CVE-2026-68743: https://github.com/SSSD/sssd/pull/9215
CVE-2026-68742: https://github.com/SSSD/sssd/pull/9216
CVE-2026-14476: https://github.com/SSSD/sssd/pull/8907
CVE-2026-14474: https://github.com/SSSD/sssd/pull/8897

Cheers,

#1143600#15
Date:
2026-09-04 13:01:35 UTC
From:
To:
Hi Luke,

please hold back the NMU for the time being.  for the time being. There
is a new team forming to maintain sssd in the future. A Salsa MR would
be appreciated though, if forking the repository works for you.

Did I just see you in the "new DD" list? If so, welcome to the project.
That being said, I'd not want to start my DD career with an NMU of a
seucrity relevant package.

Please consider subscribing to the sssd package in the tracker so that
you get all relevant communication.

Greetings
Marc

#1143600#20
Date:
2026-09-04 13:55:48 UTC
From:
To:
Hi,

I see Mike G. (?) already did a team upload which covers what I wanted
to do, so I'll drop this NMU.

Just a new DM, but I'll take your welcome ;) I was only trying to get
sssd back to testing, as I've been using sssd for years. (I have more
questions for you in PM)

Done.

Cheers,

#1143600#25
Date:
2026-09-04 21:38:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
sssd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143600@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mike Gabriel <sunweaver@debian.org> (supplier of updated sssd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 04 Sep 2026 15:54:27 +0200
Source: sssd
Architecture: source
Version: 2.13.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian SSSD Team <sssd@packages.debian.org>
Changed-By: Mike Gabriel <sunweaver@debian.org>
Closes: 1143600 1143947
Changes:
 sssd (2.13.1-2) unstable; urgency=medium
 .
   * debian/patches: Add CVE-2026-68742.diff, CVE-2026-68743.diff, and CVE-
     2026-68744.diff. (Closes: #1143600, #1143947).
     CVE-2026-68742: nss: validate addrlen in sss_nss_protocol_parse_addr()
     CVE-2026-68743: pam: validate auth_token_length in extract_authtok_v1()
     CVE-2026-68744: NSS: fix initgroups packet heap disclosure
Checksums-Sha1:
 2ec8bcec27437c7a0682fbedc2b1ed62c46d52d2 5165 sssd_2.13.1-2.dsc
 55065130bcdd70e29e07e2393bb4667d425f2403 54428 sssd_2.13.1-2.debian.tar.xz
 2c889c082caa43d4d8846a8eebe20c660e2d8dac 19490 sssd_2.13.1-2_source.buildinfo
Checksums-Sha256:
 af0e02eeed95529e2b271e597891e722d8166037e237cedcfd3be4dd0efa54e2 5165 sssd_2.13.1-2.dsc
 fdbf65bd8698db566bd9d1f743d967be0053586cb058fd3e9f8358fe0c9cbe19 54428 sssd_2.13.1-2.debian.tar.xz
 8e6dc3f339c98ed3710ff5d5f5a38406b0e2ca72dd0defff879b56f5dd4ad613 19490 sssd_2.13.1-2_source.buildinfo
Files:
 477f35abac80cb445935a5c87c3ed320 5165 utils optional sssd_2.13.1-2.dsc
 c67f816ad397f2f9e5f31466b2a6a186 54428 utils optional sssd_2.13.1-2.debian.tar.xz
 1313b4ea3bcd5731a5dceae4fb6f4bff 19490 utils optional sssd_2.13.1-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJJBAEBCgAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmqbMr4VHHN1bndlYXZl
ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxXXAP/jRBO26fg3AlKW1afmz909BK2RXN
LM9RDn/LtbOtx32bbrCKpn8p51DwE4bcfHlvnhBRyHACpgHcjLhgQ2md4UhhsiwB
3IDPmMoM1wCdg2pNADOMbj6yzmyLGJ/MPkkjoaImk1/33X1C0bs5Gw8SfizfgLCv
hT+bvtaXxQhpI09uF76NBZNdY0e6e3aL++FsQ/CQahuS/35P3R7BGMCaXWVcpJc/
8vKxJALYL2FihLm/wbhPPfC32LtA9zqfFAMtBaH4RPmg1PpUwMjljiXLpLUDnxs9
31p4RxndtQb4Yv/fv3vj56Jnq8KAOS/WO6xWCZPIIXq1XP8J/y7j921SUf824Pqy
Yu93HEw3VUST+aBvVuYj63LWu9uirnDhkLhik7of1vjfLdvEYybCbXhrbAITHjD0
tNrcRp2P3Dbdy4dicrvit0TEq6g3LgCHjnqGbjlPYxI+s5mJ0NBLArebVOca0hwG
EB8XO2Taj+aF8WtwKhhdH60IqU9JW5e3BhUSScI/NwRtsVGENOPcm/J278d1qB2Z
wI3CrigvHDDbgYm/33ELbrMVNTucim29QpNl1a46HEjfEiLnqH9WwtQ2b23aY0Ew
kSiGMTDPM9wDyGnn/KYlNCB9Ej1yNCzIoe5Gh7WWUVLkgNexigqyGF5xvuc4TRNH
7cEX1N175wmuL9A6
=/Aow
-----END PGP SIGNATURE-----