What is CVE-2026-68744?
CVE-2026-68744 is a flaw in SSSD's NSS responder, specifically in the sss_nss_protocol_fill_initgr() function. When group entries are skipped, the reply packet is not shrunk, causing uninitialized heap bytes to be transmitted to the client. A local attacker may exploit this to read potentially sensitive information, so applying the relevant SSSD security update is required.
Azərbaycanca: CVE-2026-68744, SSSD-in NSS cavab vericisindəki sss_nss_protocol_fill_initgr() funksiyasında aşkarlanmış bir boşluqdur. Qrup qeydləri atlandıqda, cavab paketinin ölçüsü azaldılmadığı üçün yaddaşdan (heap) başlanğıcda təmizlənməmiş baytlar müştəriyə ötürülür. Bu zəiflik yerli təcavüzkara həmin baytlar vasitəsilə potensial həssas məlumatları oxumağa imkan verə bilər, buna görə də SSSD-in təhlükəsiz yeniləməsini tətbiq etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which component of SSSD was the CVE-2026-68744 vulnerability discovered?
This flaw was discovered in the sss_nss_protocol_fill_initgr() function of SSSD's NSS responder.
What can a local attacker achieve by exploiting CVE-2026-68744?
A local attacker may be able to read potentially sensitive information via uninitialized heap bytes leaked in the response.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.