📌 이 취약점에 대해 확인된 사실
전부 발행처가 발표한 값입니다. 우리가 계산하거나 판단한 숫자는 하나도 없습니다.
악용 여부
심각도 (발행처 발표값)
보통4.7
3.1
secalert@redhat.com
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
악용 확률 (EPSS)
📄 원문 그대로
아래 문장은 전부 발행처가 쓴 것입니다. 번역하지 않습니다 — 보안 문서의 오역은 조치를 바꿉니다.
취약점 설명 (NVD)
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer. An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate.
참고
🧩 같은 약점 유형 — CWE-825
같은 분류의 다른 취약점입니다. 같은 실수가 제품을 가리지 않고 반복됩니다.
CVE-2026-78123strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the open…0.4%보통5.9CVE-2026-65970OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file f…0.4%보통5.3CVE-2026-102010A flaw was found in GCC. When an application calls the erase_if function on a binary heap prior…0.3%높음7.0CVE-2026-104034A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Mana…보통4.7
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.