Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11788

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

Отчет

Red Hat rates this issue as Moderate impact. The dereference control plugin in 389-ds-base does not check whether ber_init() succeeded before using the BER structure. If allocation fails, an LDAP search carrying the deref control can crash ns-slapd. The deref plugin is enabled by default, and anonymous clients can send the control when anonymous access is allowed. NVD rates this 7.5 (AC:L); Red Hat rates 5.9 (AC:H) because the NULL return from ber_init() occurs when memory allocation fails, not from a crafted control payload alone—a well-formed deref search on a server with normal free memory does not trigger the crash. Natural OOM was not demonstrated end-to-end without fault injection. Disabling the deref plugin removes the vulnerable code path entirely.

Меры по смягчению последствий

Disable the deref plugin (most effective): dsconf plugin deref disable; systemctl restart dirsrv@. Disable anonymous access (nsslapd-allow-anonymous-access=off) to raise the bar from pre-auth to authenticated exploitation. Configure memory limits as defense-in-depth: set nsslapd-maxbersize and nsslapd-conntablesize, and deploy in a cgroup with memory limits.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseAffected
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseAffected
Red Hat Enterprise Linux 8389-ds-baseAffected
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:5553217.08.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:5542417.08.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:5542517.08.2026
Red Hat Enterprise Linux 9389-ds-baseFixedRHSA-2026:5542317.08.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions389-ds-baseFixedRHSA-2026:5542117.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2485423389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser

EPSS

Процентиль: 28%
0.00346
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
nvd
2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
debian
2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plug ...

CVSS3: 5.9
github
2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 28%
0.00346
Низкий

5.9 Medium

CVSS3