Denial of Service Vulnerability in SSSD Affects Multiple Ubuntu Releases

Denial of Service Vulnerability in SSSD Affects Multiple Ubuntu Releases

First seen 1 Jun 2026, 22:50 UTC Ubuntulaunchpad.netLinuxsecurity 88% similarity 57.1

Article Content

Browse articles
ThreatCluster

A vulnerability in the System Security Services Daemon (SSSD) was discovered, affecting Ubuntu 26.04 LTS, 25.10, and 24.04 LTS. The flaw allows a local attacker to crash the SSSD PAM responder by sending specially crafted input, leading to a denial of service. The vulnerability arises from improper handling of raw bytes in the PAM passkey responder. Users are advised to update their systems to mitigate this issue. The affected package versions include sssd 2.12.0-1ubuntu5.1 for Ubuntu 26.04 LTS, among others. A standard system update will implement the necessary changes. The issue was detailed in Ubuntu Security Notice USN-8355-1.

Key Points: • A vulnerability in SSSD could lead to denial of service for multiple Ubuntu versions. • Affected versions include Ubuntu 26.04 LTS, 25.10, and 24.04 LTS. • Users should update their systems to the latest package versions to mitigate the risk.

ThreatCluster AI

Timeline

2026-06-01
SSSD vulnerability disclosed
A flaw in SSSD allows local attackers to crash the PAM responder, causing denial of service. Affected systems include Ubuntu 26.04 LTS, 25.10, and 24.04 LTS.
Ubuntu
2026-06-01
Ubuntu Security Notice USN-8355-1 published
The notice details the SSSD vulnerability and provides guidance for users to update their systems.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story