#1148326 sssd: CVE-2026-90996

Package:
src:sssd
Source:
src:sssd
Submitter:
Salvatore Bonaccorso
Date:
2026-09-18 18:35:03 UTC
Severity:
normal
Tags:
#1148326#5
Date:
2026-09-18 18:33:49 UTC
From:
To:
Hi,

The following vulnerability was published for sssd.

CVE-2026-90996[0]:
| A flaw was found in sssd. A local unprivileged user could send a
| specially crafted request with a zero-length body to the Network
| Security Services (NSS) responder. This could lead to a denial-of-
| service condition, causing the NSS responder to become unstable or
| terminate. This vulnerability affects the availability of the system
| responder.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90996
https://www.cve.org/CVERecord?id=CVE-2026-90996
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2478986

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore