Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11790

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

Отчет

Red Hat rates this issue as Moderate impact. The PBKDF2-SHA256 password storage plugin in 389-ds-base accepts unbounded iteration counts from stored password hashes. An attacker with Directory Manager access can plant a hash with extreme iterations; subsequent BIND operations hang worker threads for hours, enabling persistent denial of service. The poisoned hash persists in the database and re-triggers on every bind, so recovery requires Directory Manager access to replace the hash. This is distinct from CVE-2024-5953, which added hash length checks but not an iteration cap.

Меры по смягчению последствий

Disable nsslapd-allow-hashed-passwords (default: off) to prevent non-DM users from setting pre-hashed passwords. Restrict Directory Manager credentials; limit DM access to management networks and audit DM operations via nsslapd-auditlog. Monitor for suspicious userPassword modifications (unusual hash schemes or large base64 payloads). Monitor for unusually long bind operations to the same account, which may indicate a poisoned PBKDF2 hash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseFix deferred
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2485421389-ds-base: 389-ds-base: PBKDF2 password storage plugin unbounded iteration count denial of service

EPSS

Процентиль: 22%
0.00291
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

CVSS3: 4.9
nvd
2 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

CVSS3: 4.9
debian
2 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password s ...

CVSS3: 4.9
github
2 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 22%
0.00291
Низкий

4.9 Medium

CVSS3