PatchSiren cyber security CVE debrief
CVE-2026-104044 Red Hat CVE debrief
A local attacker can trigger a Denial of Service (DoS) in sssd by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled, disrupting authentication services on the host. This vulnerability affects sssd, a system service to access remote directories and authentication mechanisms. It is crucial for system administrators and security teams to assess exposure and prioritize patching to prevent potential disruption of authentication services.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- MEDIUM 6.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for managing sssd configurations and authentication services should assess exposure and prioritize patching to prevent potential disruption of authentication services. This includes teams managing Linux systems, authentication infrastructure, and those responsible for vulnerability management and incident response.
Why it matters
CVE-2026-104044 is a vulnerability in sssd that can lead to a denial of service when passkey authentication is enabled. System administrators and security teams should assess exposure and prioritize patching to prevent potential disruption of authentication services.
- Disruption of authentication services on the host
- Potential downtime for affected systems
- Need for verification of sssd configuration and authentication services
- Prioritization of patching for systems using sssd with passkey authentication enabled
Technical summary
A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This vulnerability affects sssd, a system service to access remote directories and authentication mechanisms, and can lead to disruption of authentication services on the host if exploited.
Defensive priority
Assess exposure and prioritize patching for systems using sssd with passkey authentication enabled.
Recommended defensive actions
- Assess exposure and prioritize patching for systems using sssd with passkey authentication enabled.
- Verify sssd configuration and authentication services.
- Monitor authentication logs for potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. Red Hat has also provided a reference for the CVE. The vulnerability has been publicly disclosed and its details are available in various sources, including the CVE Program record and NVD. However, the exact scope of affected systems and potential impact on specific deployments is not explicitly stated in the available sources. Defenders should verify sssd configurations, authentication services, and monitor authentication logs to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104044 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104044
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104044 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104044
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Sssd: sssd: denial of service via crafted passkey kerberos authentication request
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104044.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-104044
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.