A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the…
redhat·CWE-125·Published 2026-08-04