Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11787

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

Отчет

Red Hat rates this issue as Moderate impact. In 389-ds-base, internal text-based LDAP filter parsing can read up to six bytes before a heap buffer when a filter string has = at or near the start. Production builds do not crash; the practical effect is silent filter misparse—search results may be wrong, including where ACIs use targetfilter. This path is not reached by normal LDAP search filters on the wire (BER-encoded filters use a separate parser). An attacker must influence internal filter strings—for example plugin configuration (originFilter, nsUniqueAttribute), ACI definitions, or replication-delivered config. NVD rates this 6.3 (AC:L); Red Hat rates 5.0 (AC:H, PR:L) because exploitation requires those internal paths, not direct network filter injection.

Меры по смягчению последствий

No direct workaround addresses the code-level bug; network-level mitigations (proxies, WAFs, filter validation) do not apply. Mitigation measures to reduce exposure: restrict plugin configuration access (MEP originFilter, UID uniqueness nsUniqueAttribute, strict ACIs on cn=config); restrict Directory Manager access for ACI, MEP, or uniqueness plugin configuration; harden replication topology to restrict replication peers; monitor for anomalous search result sets that may indicate exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseFix deferred
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2485425389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing

EPSS

Процентиль: 8%
0.00177
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

CVSS3: 5
nvd
2 месяца назад

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

CVSS3: 5
debian
2 месяца назад

A flaw was found in 389 Directory Server. The ldap_utf8prev() function ...

CVSS3: 5
github
2 месяца назад

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 8%
0.00177
Низкий

5 Medium

CVSS3