Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11785

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

Отчет

This Moderate impact flaw in 389 Directory Server allows an authenticated, non-administrator user to obtain partial stack address information. The SSO token feature, which is enabled by default in Red Hat Directory Server, leaks the lower 32 bits of a stack address in LDAP extended operation responses, reducing Address Space Layout Randomization (ASLR) entropy but not leading to a full bypass.

Меры по смягчению последствий

Option 1 (Recommended): Disable the SSO token feature entirely: dsconf config replace nsslapd-enable-ldapssotoken=off. This prevents the vulnerable code path from being reached but disables SSO token functionality for all users. Option 2: Restrict network access to LDAP ports (389/636) to trusted networks via firewall rules. Note: Removing the SSO token secret from configuration does not mitigate the vulnerability — the server auto-generates a new secret at startup.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseNot affected
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseNot affected
Red Hat Enterprise Linux 8389-ds-baseNot affected
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2485427389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in SSO token handler

EPSS

Процентиль: 8%
0.00179
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

CVSS3: 4.3
nvd
2 месяца назад

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

CVSS3: 4.3
debian
2 месяца назад

A flaw was found in 389 Directory Server. A type confusion in the SSO ...

CVSS3: 4.3
github
2 месяца назад

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 8%
0.00179
Низкий

4.3 Medium

CVSS3