A flaw was found in sssd-kcm. A local user or process able to connect to the sssd-kcm UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the sssd-kcm responder, resulting in a Denial of Service (DoS) for affected deployments.