Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11610

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

Отчет

Red Hat rates this issue as Important impact. After a successful SASL bind with integrity protection (SSF > 0), an authenticated remote attacker can send a crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv(). Up to roughly two megabytes of attacker-controlled data can overflow the buffer, reliably crashing ns-slapd on production builds. Exploitation requires a valid SASL-authenticated LDAP session, not Directory Manager access. Any user who can bind with SASL mechanisms such as GSSAPI/Kerberos or DIGEST-MD5 can trigger the denial of service. In deployments where domain users, enrolled hosts, and service accounts routinely authenticate to the directory over Kerberos, the attack surface includes any such principal with network access to LDAP. This flaw is independent of CVE-2025-14905, which patched a separate heap overflow in schema.c and did not modify sasl_io.c.

Меры по смягчению последствий

There is no complete workaround for this flaw. Mitigations that reduce exposure:

  1. Restrict network access to LDAP ports (389/636) to trusted networks only. Note: In FreeIPA/IdM deployments, enrolled clients require LDAP access and this may not be practical.
  2. If DIGEST-MD5 is not required, disable it via nsslapd-allowed-sasl-mechanisms in cn=config. GSSAPI/Kerberos cannot be disabled in FreeIPA/IdM without breaking domain authentication.
  3. Monitor for oversized LDAP UNBIND packets (standard UNBIND is 7 bytes; alert on UNBIND packets exceeding ~100 bytes).
  4. Lowering nsslapd-maxbersize reduces maximum overflow size but does not eliminate the vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseNot affected
Red Hat Enterprise Linux 6389-ds-baseWill not fix
Red Hat Directory Server 11.5 E4S for RHEL 8redhat-dsFixedRHSA-2026:3620407.07.2026
Red Hat Directory Server 11.7 E4S for RHEL 8redhat-dsFixedRHSA-2026:3620807.07.2026
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:3620007.07.2026
Red Hat Directory Server 12.2 E4S for RHEL 9redhat-dsFixedRHSA-2026:3664108.07.2026
Red Hat Directory Server 12.4 E4S for RHEL 9redhat-dsFixedRHSA-2026:3620907.07.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:3619607.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:3667008.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2484414389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND

EPSS

Процентиль: 46%
0.00627
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
25 дней назад

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

CVSS3: 8.8
nvd
25 дней назад

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

CVSS3: 8.8
debian
25 дней назад

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...

CVSS3: 8.8
github
25 дней назад

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

rocky
23 дня назад

Important: 389-ds:1.4 security update

EPSS

Процентиль: 46%
0.00627
Низкий

8.8 High

CVSS3