CVE-2026-80048: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-80048 is a local Denial of Service vulnerability in sssd-kcm, the Kerberos Credential Manager component of SSSD (System Security Services Daemon). A local user or process with access to the sssd-kcm UNIX socket can exploit this flaw by sending a large request length header and then stalling the connection, causing the responder to preallocate significant memory and ultimately exhausting available memory. Affected software includes sssd (specifically sssd-2.12.0-1.el10) on Red Hat Enterprise Linux and related products including openshift/ose-rhel-coreos-8 and openshift/ose-rhel-coreos-9. The vulnerability was reported on 2026-05-18 and publicly disclosed on 2026-10-06. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in the kcm_recv_data() function within src/responder/kcm/kcmsrv_cmd.c. When a client connects to the sssd-kcm UNIX socket and sends a 4-byte length header declaring a large payload (up to KCM_PACKET_MAX_SIZE of 10 MiB), the code immediately allocates the full declared buffer size via talloc_array() before any payload bytes arrive. If the client then stalls without sending the body, the caller handles the resulting EAGAIN by keeping the connection open, leaving the attacker-controlled allocation pinned to the live connection context until the client disconnects or the client_idle_timeout (default 300 seconds) expires. With a default fd_limit of 2048, an attacker can open hundreds of concurrent stalled connections, each pinning up to 10 MiB, leading to memory exhaustion. A proof-of-concept Python script using socket and struct.pack to send only the length header across many connections is documented in the Red Hat Bugzilla report (Red Hat Bugzilla).

Impact

Successful exploitation causes memory exhaustion within the sssd-kcm responder process, rendering it unable to respond to any further requests. This results in a full Denial of Service of the system's Kerberos Cache Manager, meaning any user or service depending on KRB5, GSSAPI, or SASL authentication will be unable to authenticate to local or remote services for the duration of the attack. There is no confidentiality or integrity impact; the vulnerability is strictly an availability issue confined to the sssd-kcm responder's security scope (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code has been released beyond the conceptual PoC script documented in the Red Hat Bugzilla report, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is limited to local attackers with the ability to connect to the sssd-kcm UNIX socket, which requires the sssd-kcm responder to be explicitly enabled — a non-default configuration on Red Hat Enterprise Linux (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Verify prerequisites: Confirm that the target system has sssd-kcm installed and the responder is enabled. Check with systemctl status sssd-kcm.socket and verify the socket exists at the default path /var/run/.heim_org.h5l.kcm-socket.
  2. Obtain local access: Gain a local user account or process context on the target system that has permission to connect to the sssd-kcm UNIX socket.
  3. Open concurrent stalled connections: Using a script (e.g., Python with the socket and struct modules), open a large number of concurrent UNIX socket connections to /var/run/.heim_org.h5l.kcm-socket. For each connection, send only the 4-byte big-endian length header declaring the maximum payload size (struct.pack(">I", 10*1024*1024)) without sending any body bytes.
  4. Stall connections: Keep all connections open without sending further data, causing sssd-kcm to retain a ~10 MiB allocation per connection while waiting for the body that never arrives.
  5. Exhaust memory: Maintain the stalled connections until the sssd-kcm responder's memory is exhausted (approximately N * 10 MiB where N is the number of connections), causing it to stop responding to legitimate requests and achieving a full DoS of the Kerberos Cache Manager (Red Hat Bugzilla).

Indicators of compromise

  • Process: Rapidly increasing RSS (Resident Set Size) of the sssd-kcm process observable via top, ps, or /proc/<pid>/status; the process becomes unresponsive to legitimate KCM requests.
  • Network/Socket: Unusually high number of concurrent connections to the sssd-kcm UNIX socket at /var/run/.heim_org.h5l.kcm-socket, detectable via ss -x or lsof.
  • Logs: SSSD logs (typically /var/log/sssd/sssd_kcm.log) showing repeated EAGAIN / "Retry later" trace messages from kcm_recv() for many simultaneous connections; authentication failures for KRB5/GSSAPI/SASL services in system logs (/var/log/secure or journalctl).
  • System: System-wide memory pressure indicators such as elevated swap usage or OOM killer activity in dmesg or journalctl -k coinciding with sssd-kcm unresponsiveness (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has classified this as Moderate impact and notes that no configuration-based mitigation fully meets their deployment criteria; the recommended fix is a code-level patch implementing incremental buffer allocation in kcm_recv_data(). As interim mitigations, administrators should restrict access to the sssd-kcm UNIX socket via filesystem permissions to limit which local users and processes can connect. Lowering client_idle_timeout (from the default 300 seconds) and fd_limit in the SSSD configuration reduces the window and scale of memory pinning. Deployments that do not require sssd-kcm should disable it (systemctl disable --now sssd-kcm.socket) until a patched package is available (Red Hat CVE, Red Hat Bugzilla).

Community reactions

The vulnerability was credited to "Aisle Research" in the Red Hat Bugzilla report. Red Hat classified it as Moderate severity, noting it is local and configuration-dependent, with the sssd-kcm responder not enabled by default on RHEL. No significant broader media coverage or notable researcher commentary beyond the official Red Hat and GitHub Advisory disclosures has been identified at this time (Red Hat CVE, Github Advisory).

Additional resources


Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106547HIGH8.5
  • HDF5 logoHDF5
  • hdf5
NoYesOct 06, 2026
CVE-2026-43598HIGH7.7
  • Linux Debian logoLinux Debian
  • rccl
NoNoOct 06, 2026
CVE-2026-19029MEDIUM6.8
  • HDF5 logoHDF5
  • cpe:2.3:a:hdfgroup:hdf5
NoYesOct 06, 2026
CVE-2026-106061MEDIUM5.5
  • Linux Debian logoLinux Debian
  • gimp-devel-tools
NoNoOct 07, 2026
CVE-2026-80048NONEN/A
  • Linux Debian logoLinux Debian
  • sssd-winbind-idmap
NoNoOct 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management