Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11774

Опубликовано: 04 июн. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.

Отчет

Red Hat rates this issue as Important. After a successful SASL bind with integrity protection, an authenticated attacker can send a SASL-framed packet whose length prefix wraps when processed in sasl_io_start_packet(), bypassing nsslapd-maxsasliosize and causing a heap buffer overflow of up to approximately two megabytes of attacker-controlled data. This flaw is independent of CVE-2025-14905 (schema.c). Any domain user with a Kerberos ticket can trigger it remotely after GSSAPI authentication. Red Hat assigns C:L/I:L rather than Critical because remote code execution on current platforms with glibc 2.32+ is blocked by tcache safe linking; RCE was demonstrated on RHEL 8 with glibc 2.28 but required a heap address leak. Denial of service is reliable on all platforms.

Меры по смягчению последствий

No complete workaround exists; nsslapd-maxsasliosize is bypassed by the integer overflow. Mitigations that reduce exposure: restrict SASL mechanisms (disable DIGEST-MD5 if not required; GSSAPI cannot be disabled in FreeIPA/IdM without breaking Kerberos authentication); firewall LDAP ports (389/636) to trusted networks; monitor for SASL-framed packets with length prefix 0xFFFFFFFC through 0xFFFFFFFF; enable audit logging (nsslapd-auditlog-logging-enabled: on); on RHEL 8, upgrading glibc reduces RCE exploitability but does not eliminate DoS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseNot affected
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Directory Server 11.5 E4S for RHEL 8redhat-dsFixedRHSA-2026:3620407.07.2026
Red Hat Directory Server 11.7 E4S for RHEL 8redhat-dsFixedRHSA-2026:3620807.07.2026
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:3620007.07.2026
Red Hat Directory Server 12.2 E4S for RHEL 9redhat-dsFixedRHSA-2026:3664108.07.2026
Red Hat Directory Server 12.4 E4S for RHEL 9redhat-dsFixedRHSA-2026:3620907.07.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:3619607.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:3667008.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2484916389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow

EPSS

Процентиль: 48%
0.0067
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 2 месяцев назад

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.

CVSS3: 7.6
nvd
около 2 месяцев назад

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.

CVSS3: 7.6
debian
около 2 месяцев назад

An integer overflow flaw was found in the SASL I/O layer of 389 Direct ...

CVSS3: 7.6
github
около 2 месяцев назад

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.

rocky
23 дня назад

Important: 389-ds:1.4 security update

EPSS

Процентиль: 48%
0.0067
Низкий

7.6 High

CVSS3