CVE-2026-104047:
NixOS 취약성 분석 및 완화
개요
CVE-2026-104047 is an OData filter injection vulnerability in SSSD (System Security Services Daemon) that allows a local, low-privileged user to manipulate directory query filters when SSSD is configured to use Microsoft Entra ID as the identity provider. By submitting a crafted lookup request containing unsanitized single-quote characters, an attacker can escape intended OData string literals and broaden directory queries, resulting in unauthorized information disclosure. The vulnerability was reported on May 18, 2026, publicly disclosed on October 6, 2026, and affects sssd-2.12.0-1.el10 and related Red Hat products including openshift/ose-rhel-coreos-8 and openshift/ose-rhel-coreos-9. It carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE, GitHub Advisory).
기술적 세부 사항
The root cause is CWE-140 (Improper Neutralization of Delimiters): the entra_id_lookup() function in src/oidc_child/oidc_child_id.c constructs OData $filter expressions by directly interpolating user-controlled input into single-quoted string literals using talloc_asprintf(), without escaping embedded single quotes. Only URL encoding is applied afterward, which does not prevent injection at the OData layer. An attacker with local access can trigger a name-based lookup with a crafted value such as a') or startsWith(userPrincipalName,'') or ('1' eq '1, causing the generated $filter to include attacker-controlled predicate logic. This vulnerability is only exploitable when SSSD is explicitly configured with idp_type=entra_id — a non-default configuration — and valid directory client credentials are present (Red Hat Bugzilla, Red Hat CVE).
영향
Successful exploitation allows a local, low-privileged user to retrieve broader directory metadata from Microsoft Entra ID than they are authorized to access, potentially exposing user principal names, email addresses, and display names of other directory objects. The injected query logic can also cause increased parsing, processing, and cache activity in SSSD, resulting in a minor availability impact. The vulnerability does not enable arbitrary code execution, remote access, or host-level privilege escalation, and the scope of exposed data is bounded by the directory permissions granted to the SSSD service account (Red Hat CVE, Red Hat Bugzilla).
악용 가능성
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Red Hat CVE, GitHub Advisory). The vulnerability is not automatable (per NVD SSVC assessment) and requires a specific non-default configuration (idp_type=entra_id) to be exploitable. The EPSS score is 0.0, reflecting very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The issue was discovered by AISLE Research in partnership with Red Hat (Red Hat CVE).
착취 단계
- Verify preconditions: Confirm the target system runs
sssd-2.12.0-1.el10(or an affected version) with SSSD configured to useidp_type=entra_idand valid Entra ID directory client credentials and scopes. - Obtain local access: Authenticate to the target system as any low-privileged local user — no elevated privileges are required.
- Craft the injection payload: Construct a lookup value that breaks out of the OData single-quoted string literal, for example:
a') or startsWith(userPrincipalName,'') or ('1' eq '1. - Trigger the lookup: Initiate a name-based user or group lookup using the crafted value (e.g., via
getent passwdoridwith the crafted name), which causes SSSD to callentra_id_lookup()inoidc_child_id.c. - Observe injected filter: Enable SSSD debug logging or
--libcurl-debugand inspect the outgoing HTTP request to the Entra ID/users?$filter=or/groups?$filter=endpoint; after URL decoding, the$filterwill contain the injectedor ...predicate logic. - Collect overbroad results: Review the response, which may include directory records beyond the intended single-user match, and observe that results are iterated and stored in the SSSD cache (Red Hat Bugzilla).
타협의 징후
- Logs: SSSD debug logs or
--libcurl-debugoutput showing outgoing requests to the Entra ID/users?$filter=or/groups?$filter=endpoint with URL-encoded single quotes (%27) or unexpectedorpredicates in the filter string. - Logs: SSSD logs recording unexpectedly large result sets from Entra ID directory queries, or repeated lookups with unusual username formats containing special characters.
- Network: Outbound HTTPS requests from the SSSD
oidc_childprocess to Microsoft Graph API endpoints (graph.microsoft.com) with abnormally complex or lengthy$filterquery parameters. - File System: Unexpected or unusually large SSSD cache entries (
/var/lib/sss/db/) containing directory records for users not expected to be present on the system (Red Hat Bugzilla).
완화 및 해결 방법
A patch is available as of October 6, 2026, tracked in Red Hat Bugzilla bug 2478616; the fix introduces an odata_escape_single_quotes() helper function that doubles single quotes in OData string literals before interpolation, preventing injection. Red Hat notes that no configuration-based mitigation fully eliminates the flaw, but recommends: (1) avoiding enabling the Entra ID provider path (idp_type=entra_id) where not required; (2) restricting which users can trigger name-based lookups with untrusted input; and (3) monitoring for unexpectedly broad directory $filter requests. Organizations should apply the available patch from Red Hat and review SSSD configurations to ensure Entra ID integration is only enabled where necessary (Red Hat CVE, Red Hat Bugzilla).
커뮤니티 반응
Red Hat rated this vulnerability as Moderate impact, noting that exploitation requires low-privileged local access and a non-default Entra ID configuration not typically enabled in standard RHEL environments. The issue was discovered by AISLE Research in partnership with Red Hat, following a coordinated disclosure process. No significant broader media coverage or notable researcher commentary beyond the official Red Hat advisory has been identified at this time (Red Hat CVE).
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 NixOS 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."