CVE-2026-90996 MEDIUM

CVE-2026-90996: Sssd: sssd: denial of service in nss responder via crafted zero-length requests

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-191
Published September 14, 2026
Last update September 14, 2026

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.

Key dates

02Disclosure timeline

September 14, 2026 CVE published