
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-80048 is a local Denial of Service vulnerability in sssd-kcm, the Kerberos Credential Manager component of SSSD (System Security Services Daemon). A local user or process with access to the sssd-kcm UNIX socket can exploit this flaw by sending a large request length header and then stalling the connection, causing the responder to preallocate significant memory and ultimately exhausting available memory. Affected software includes sssd (specifically sssd-2.12.0-1.el10) on Red Hat Enterprise Linux and related products including openshift/ose-rhel-coreos-8 and openshift/ose-rhel-coreos-9. The vulnerability was reported on 2026-05-18 and publicly disclosed on 2026-10-06. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in the kcm_recv_data() function within src/responder/kcm/kcmsrv_cmd.c. When a client connects to the sssd-kcm UNIX socket and sends a 4-byte length header declaring a large payload (up to KCM_PACKET_MAX_SIZE of 10 MiB), the code immediately allocates the full declared buffer size via talloc_array() before any payload bytes arrive. If the client then stalls without sending the body, the caller handles the resulting EAGAIN by keeping the connection open, leaving the attacker-controlled allocation pinned to the live connection context until the client disconnects or the client_idle_timeout (default 300 seconds) expires. With a default fd_limit of 2048, an attacker can open hundreds of concurrent stalled connections, each pinning up to 10 MiB, leading to memory exhaustion. A proof-of-concept Python script using socket and struct.pack to send only the length header across many connections is documented in the Red Hat Bugzilla report (Red Hat Bugzilla).
Successful exploitation causes memory exhaustion within the sssd-kcm responder process, rendering it unable to respond to any further requests. This results in a full Denial of Service of the system's Kerberos Cache Manager, meaning any user or service depending on KRB5, GSSAPI, or SASL authentication will be unable to authenticate to local or remote services for the duration of the attack. There is no confidentiality or integrity impact; the vulnerability is strictly an availability issue confined to the sssd-kcm responder's security scope (Red Hat CVE).
No public proof-of-concept exploit code has been released beyond the conceptual PoC script documented in the Red Hat Bugzilla report, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is limited to local attackers with the ability to connect to the sssd-kcm UNIX socket, which requires the sssd-kcm responder to be explicitly enabled — a non-default configuration on Red Hat Enterprise Linux (Red Hat CVE, Red Hat Bugzilla).
sssd-kcm installed and the responder is enabled. Check with systemctl status sssd-kcm.socket and verify the socket exists at the default path /var/run/.heim_org.h5l.kcm-socket.sssd-kcm UNIX socket.socket and struct modules), open a large number of concurrent UNIX socket connections to /var/run/.heim_org.h5l.kcm-socket. For each connection, send only the 4-byte big-endian length header declaring the maximum payload size (struct.pack(">I", 10*1024*1024)) without sending any body bytes.sssd-kcm to retain a ~10 MiB allocation per connection while waiting for the body that never arrives.sssd-kcm responder's memory is exhausted (approximately N * 10 MiB where N is the number of connections), causing it to stop responding to legitimate requests and achieving a full DoS of the Kerberos Cache Manager (Red Hat Bugzilla).sssd-kcm process observable via top, ps, or /proc/<pid>/status; the process becomes unresponsive to legitimate KCM requests.sssd-kcm UNIX socket at /var/run/.heim_org.h5l.kcm-socket, detectable via ss -x or lsof./var/log/sssd/sssd_kcm.log) showing repeated EAGAIN / "Retry later" trace messages from kcm_recv() for many simultaneous connections; authentication failures for KRB5/GSSAPI/SASL services in system logs (/var/log/secure or journalctl).dmesg or journalctl -k coinciding with sssd-kcm unresponsiveness (Red Hat Bugzilla).Red Hat has classified this as Moderate impact and notes that no configuration-based mitigation fully meets their deployment criteria; the recommended fix is a code-level patch implementing incremental buffer allocation in kcm_recv_data(). As interim mitigations, administrators should restrict access to the sssd-kcm UNIX socket via filesystem permissions to limit which local users and processes can connect. Lowering client_idle_timeout (from the default 300 seconds) and fd_limit in the SSSD configuration reduces the window and scale of memory pinning. Deployments that do not require sssd-kcm should disable it (systemctl disable --now sssd-kcm.socket) until a patched package is available (Red Hat CVE, Red Hat Bugzilla).
The vulnerability was credited to "Aisle Research" in the Red Hat Bugzilla report. Red Hat classified it as Moderate severity, noting it is local and configuration-dependent, with the sssd-kcm responder not enabled by default on RHEL. No significant broader media coverage or notable researcher commentary beyond the official Red Hat and GitHub Advisory disclosures has been identified at this time (Red Hat CVE, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."