PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104044 Red Hat CVE debrief

A local attacker can trigger a Denial of Service (DoS) in sssd by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled, disrupting authentication services on the host. This vulnerability affects sssd, a system service to access remote directories and authentication mechanisms. It is crucial for system administrators and security teams to assess exposure and prioritize patching to prevent potential disruption of authentication services.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
MEDIUM 6.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-08
Advisory published
2026-10-06
Advisory updated
2026-10-08

Who should care

System administrators and security teams responsible for managing sssd configurations and authentication services should assess exposure and prioritize patching to prevent potential disruption of authentication services. This includes teams managing Linux systems, authentication infrastructure, and those responsible for vulnerability management and incident response.

Why it matters

CVE-2026-104044 is a vulnerability in sssd that can lead to a denial of service when passkey authentication is enabled. System administrators and security teams should assess exposure and prioritize patching to prevent potential disruption of authentication services.

  • Disruption of authentication services on the host
  • Potential downtime for affected systems
  • Need for verification of sssd configuration and authentication services
  • Prioritization of patching for systems using sssd with passkey authentication enabled

Technical summary

A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This vulnerability affects sssd, a system service to access remote directories and authentication mechanisms, and can lead to disruption of authentication services on the host if exploited.

Defensive priority

Assess exposure and prioritize patching for systems using sssd with passkey authentication enabled.

Recommended defensive actions

  • Assess exposure and prioritize patching for systems using sssd with passkey authentication enabled.
  • Verify sssd configuration and authentication services.
  • Monitor authentication logs for potential exploitation attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. Red Hat has also provided a reference for the CVE. The vulnerability has been publicly disclosed and its details are available in various sources, including the CVE Program record and NVD. However, the exact scope of affected systems and potential impact on specific deployments is not explicitly stated in the available sources. Defenders should verify sssd configurations, authentication services, and monitor authentication logs to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104044 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104044

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104044 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104044

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.