diff --git a/dynamic-layers/networking-layer/recipes-security/sssd/files/CVE-2026-68743.patch b/dynamic-layers/networking-layer/recipes-security/sssd/files/CVE-2026-68743.patch
new file mode 100644
index 0000000..f5b8345
--- /dev/null
+++ b/dynamic-layers/networking-layer/recipes-security/sssd/files/CVE-2026-68743.patch
@@ -0,0 +1,43 @@
+From bef9d12617f22335e65447609a2724a68c1bf68a Mon Sep 17 00:00:00 2001
+From: Alexey Tikhonov <atikhono@redhat.com>
+Date: Tue, 4 Aug 2026 20:51:07 +0200
+Subject: [PATCH] pam: validate auth_token_length in extract_authtok_v1()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The check mimics one existing in `extract_authtok_v2()`
+
+:fixes: CVE-2026-68743
+
+Assisted-By: Claude Code (Opus 4.6)
+Reviewed-by: Pavel Březina <pbrezina@redhat.com>
+Reviewed-by: Sumit Bose <sbose@redhat.com>
+
+CVE: CVE-2026-68743
+Upstream-Status: Backport [https://github.com/SSSD/sssd/commit/bef9d12617f22335e65447609a2724a68c1bf68a]
+
+Signed-off-by: Rohini Sangam <rsangam@mvista.com>
+---
+ src/responder/pam/pamsrv_cmd.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/src/responder/pam/pamsrv_cmd.c b/src/responder/pam/pamsrv_cmd.c
+index d4cb421..a6145d1 100644
+--- a/src/responder/pam/pamsrv_cmd.c
++++ b/src/responder/pam/pamsrv_cmd.c
+@@ -419,6 +419,11 @@ static int extract_authtok_v1(struct sss_auth_token *tok,
+ 
+     SAFEALIGN_COPY_UINT32_CHECK(&auth_token_type, &body[*c], blen, c);
+     SAFEALIGN_COPY_UINT32_CHECK(&auth_token_length, &body[*c], blen, c);
++
++    if (*c + auth_token_length > blen || SIZE_T_OVERFLOW(*c, auth_token_length)) {
++        return EINVAL;
++    }
++
+     auth_token_data = body+(*c);
+ 
+     switch (auth_token_type) {
+-- 
+2.44.4
+
diff --git a/dynamic-layers/networking-layer/recipes-security/sssd/sssd_2.9.7.bb b/dynamic-layers/networking-layer/recipes-security/sssd/sssd_2.9.7.bb
index f92fe65..52dce32 100644
--- a/dynamic-layers/networking-layer/recipes-security/sssd/sssd_2.9.7.bb
+++ b/dynamic-layers/networking-layer/recipes-security/sssd/sssd_2.9.7.bb
@@ -26,6 +26,7 @@ SRC_URI = "https://github.com/SSSD/sssd/releases/download/${PV}/${BP}.tar.gz \
            file://musl_fixup.patch \
            file://0001-sssctl-add-error-analyzer.patch \
            file://CVE-2025-11561.patch \
+           file://CVE-2026-68743.patch \
            "
 SRC_URI[sha256sum] = "6b5284a4d72b67c0897699794360d79e0f67461957e20273c2649f025e76c248"
 
