SSSD Vulnerabilities in Ubuntu Lead to Potential Denial of Service

SSSD Vulnerabilities in Ubuntu Lead to Potential Denial of Service

First seen 3 Sep 2026, 13:21 UTC LinuxsecurityUbuntu 45.0

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in the System Security Services Daemon (SSSD) have been identified in Ubuntu versions 22.04, 24.04, and 26.04 LTS. The first vulnerability allows a physically proximate attacker to crash SSSD through manipulation of smartcards or Yubikeys, affecting user login capabilities. The second vulnerability involves improper validation of authentication token lengths, which could also lead to SSSD crashes and denial of service. Users of affected systems are advised to update their packages to the latest versions to mitigate these risks. The vulnerabilities have been assigned USN-8672-1 and USN-8718-1 respectively. After applying updates, a restart of SSSD is required to implement the changes. No active exploitation has been reported yet, but the vulnerabilities pose significant risks to system availability.

Key Points: • Two vulnerabilities in SSSD affect Ubuntu 22.04, 24.04, and 26.04 LTS. • One vulnerability allows denial of service via smartcard or Yubikey manipulation. • Another vulnerability involves improper validation of authentication token lengths.

Timeline

2026-09-02
USN-8672-1 published
Ubuntu released a security notice regarding SSSD crashing due to smartcard interactions.
Linuxsecurity
2026-09-03
USN-8718-1 published
Ubuntu disclosed another SSSD vulnerability related to authentication token length validation.
Ubuntu