| Name | CVE-2026-12610 |
| Description | A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1141323 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| sssd (PTS) | bullseye | 2.4.1-2 | vulnerable |
| bullseye (security) | 2.4.1-2+deb11u1 | vulnerable | |
| bookworm | 2.8.2-4+deb12u1 | vulnerable | |
| trixie | 2.10.1-2 | vulnerable | |
| sid | 2.12.0-4 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| sssd | source | (unstable) | (unfixed) | 1141323 |
[trixie] - sssd <no-dsa> (Minor issue)
[bookworm] - sssd <postponed> (Minor issue)
[bullseye] - sssd <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2490288
https://github.com/SSSD/sssd/issues/8796
https://github.com/SSSD/sssd/commit/fa7a55949a30fed064a28ea6f0c801fc5e8c5ba7 (master)
https://github.com/SSSD/sssd/commit/f2c69b916f5fe53a930aa39c2078b248b83bc2b4 (sssd-2-13 branch)
https://github.com/SSSD/sssd/commit/db7ffa3ea6a971bb84bc54558ca7217751724334 (sssd-2-9 branch)