A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 3.3 | 1.8 | 1.4 |
| 3.1 | Primary | cve.org | 3.3 | — | — |
| 3.1 | Primary | cve.org | 3.3 | — | — |
| 3.1 | Secondary | NVD | 3.3 | 1.8 | 1.4 |
| 3.1 | Secondary | ENISA EUVD | 3.3 | — | — |