CVE-2026-90463

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.

  • Published Sep 14, 2026
  • CVSS 4.0 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90463 at the National Vulnerability Database