[From nobody Fri Sep  4 22:41:10 2026
Received: (at submit) by bugs.debian.org; 8 Aug 2026 18:41:24 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00, FOURLA,
 FROMDEVELOPER, 
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 13; hammy, 149; neutral, 56; spammy,
 1. spammytokens:0.941-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--H*F:U*carnil, 0.000-+--H*Ad:N*Bug, 0.000-+--HTo:N*Debian
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1wslz1-002j3g-38
 for submit@bugs.debian.org; Sat, 08 Aug 2026 18:41:24 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: sssd: CVE-2026-68743
Message-ID: &lt;178621448197.104314.5802457654939424318.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Sat, 08 Aug 2026 20:41:21 +0200
Delivered-To: submit@bugs.debian.org

Source: sssd
Version: 2.12.0-4
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerability was published for sssd.

Note at time of writing this bugreport there is only the Red Hat
bugzilla linked below. Might you as with the other current open CVEs
reach out to upstream to see if, where they are already reported and
tracked? Currently this is not very clear.

CVE-2026-68743[0]:
| A flaw was found in SSSD. The extract_authtok_v1() function in the
| PAM responder does not validate the auth_token_length field against
| the remaining buffer size before processing. A local attacker can
| exploit this via a crafted protocol v1 request to the PAM responder
| socket, causing an out-of-bounds read and process crash, resulting
| in a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-68743
    https://www.cve.org/CVERecord?id=CVE-2026-68743
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2509760

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
]