Описание
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
Отчет
Red Hat rates this issue as Important impact. After a successful SASL bind with integrity protection (SSF > 0), an authenticated remote attacker can send a crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv(). Up to roughly two megabytes of attacker-controlled data can overflow the buffer, reliably crashing ns-slapd on production builds. Exploitation requires a valid SASL-authenticated LDAP session, not Directory Manager access. Any user who can bind with SASL mechanisms such as GSSAPI/Kerberos or DIGEST-MD5 can trigger the denial of service. In deployments where domain users, enrolled hosts, and service accounts routinely authenticate to the directory over Kerberos, the attack surface includes any such principal with network access to LDAP. This flaw is independent of CVE-2025-14905, which patched a separate heap overflow in schema.c and did not modify sasl_io.c.
Меры по смягчению последствий
There is no complete workaround for this flaw. Mitigations that reduce exposure:
- Restrict network access to LDAP ports (389/636) to trusted networks only. Note: In FreeIPA/IdM deployments, enrolled clients require LDAP access and this may not be practical.
- If DIGEST-MD5 is not required, disable it via nsslapd-allowed-sasl-mechanisms in cn=config. GSSAPI/Kerberos cannot be disabled in FreeIPA/IdM without breaking domain authentication.
- Monitor for oversized LDAP UNBIND packets (standard UNBIND is 7 bytes; alert on UNBIND packets exceeding ~100 bytes).
- Lowering nsslapd-maxbersize reduces maximum overflow size but does not eliminate the vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | ||
| Red Hat Directory Server 13 | 389-ds-base | Not affected | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Will not fix | ||
| Red Hat Directory Server 11.5 E4S for RHEL 8 | redhat-ds | Fixed | RHSA-2026:36204 | 07.07.2026 |
| Red Hat Directory Server 11.7 E4S for RHEL 8 | redhat-ds | Fixed | RHSA-2026:36208 | 07.07.2026 |
| Red Hat Directory Server 11.9 for RHEL 8 | redhat-ds | Fixed | RHSA-2026:36200 | 07.07.2026 |
| Red Hat Directory Server 12.2 E4S for RHEL 9 | redhat-ds | Fixed | RHSA-2026:36641 | 08.07.2026 |
| Red Hat Directory Server 12.4 E4S for RHEL 9 | redhat-ds | Fixed | RHSA-2026:36209 | 07.07.2026 |
| Red Hat Enterprise Linux 10 | 389-ds-base | Fixed | RHSA-2026:36196 | 07.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | 389-ds-base | Fixed | RHSA-2026:36670 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
EPSS
8.8 High
CVSS3