{
  "id": "CVE-2026-104037",
  "url": "https://spydr.io/cve/CVE-2026-104037",
  "published": "2026-10-06T01:16:34.707Z",
  "modified": "2026-10-06T15:09:20.387Z",
  "score": 5.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "score_source": "redhat.com",
  "epss": 0.00095,
  "epss_percentile": 0.00624,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "poc",
  "vendors": [
    "Red Hat"
  ],
  "products": [
    "Red Hat Enterprise Linux 10",
    "Red Hat Enterprise Linux 6",
    "Red Hat Enterprise Linux 7",
    "Red Hat Enterprise Linux 8",
    "Red Hat Enterprise Linux 9",
    "Red Hat OpenShift Container Platform 4"
  ],
  "cwes": [
    "CWE-125"
  ],
  "description": "A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS).",
  "status": "Awaiting Analysis",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-104037",
      "tags": []
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479030",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-104037",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
