What is CVE-2026-68743?
CVE-2026-68743 is a vulnerability in SSSD where the extract_authtok_v1() function in the PAM responder fails to validate the auth_token_length field against the remaining buffer size. A local attacker can exploit this via a crafted protocol v1 request, leading to an out-of-bounds read. Applying the latest SSSD updates is recommended.
Azərbaycanca: CVE-2026-68743, SSSD (System Security Services Daemon) proqramında aşkar edilmiş boşluqdur. PAM cavablandırıcısındakı extract_authtok_v1() funksiyası bufer ölçüsünü yoxlamadığı üçün, yerli təcavüzkar xüsusi hazırlanmış sorğu vasitəsilə out-of-bounds oxuma və ya təsirə yol aça bilər. SSSD-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
What component and vulnerability type is associated with CVE-2026-68743?
The vulnerability is in the extract_authtok_v1() function of the PAM responder in SSSD. It leads to an out-of-bounds read due to improper validation of the buffer size.
What privileges does an attacker need to exploit CVE-2026-68743?
The attacker requires local access. They can exploit the vulnerability by sending a crafted protocol v1 request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.