Hi, The following vulnerability was published for sssd. Note at time of writing this bugreport there is only the Red Hat bugzilla linked below. Might you as with the other current open CVEs reach out to upstream to see if, where they are already reported and tracked? Currently this is not very clear. CVE-2026-68743[0]: | A flaw was found in SSSD. The extract_authtok_v1() function in the | PAM responder does not validate the auth_token_length field against | the remaining buffer size before processing. A local attacker can | exploit this via a crafted protocol v1 request to the PAM responder | socket, causing an out-of-bounds read and process crash, resulting | in a denial of service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-68743 https://www.cve.org/CVERecord?id=CVE-2026-68743 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2509760 Please adjust the affected versions in the BTS as needed. Regards, Salvatore