SSSD contains an out-of-bounds read flaw in the sss_autofs_cmd_getautomntent() and sss_autofs_cmd_getautomntbyname() functions of src/responder/autofs/autofssrv_cmd.c that may allow a remote denial of service. With a specially crafted package, a remote attacker can cause the system to crash.