CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104036
MEDIUMCVSS 5.8NVD feed
Published 6 October 2026 · tracked since 6 October 2026
Description
A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105472 MEDIUM 6.3
- CVE-2026-105782 HIGH 7.5
- CVE-2026-105784 MEDIUM 4.6
- CVE-2026-105471 HIGH 7.3
- CVE-2026-105757 MEDIUM 6.5
- CVE-2026-105758 MEDIUM 5.3
- CVE-2026-105759 MEDIUM 5.9
- CVE-2026-105469 HIGH 7.3
- CVE-2026-105470 HIGH 7.3
- CVE-2026-105744 HIGH 7.5