Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11791

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

Отчет

Red Hat rates this issue as Moderate impact. During schema reload in 389-ds-base, attr_syntax_swap_ht() frees attribute syntax nodes unconditionally, bypassing the refcount-based deferred deletion used elsewhere. An administrator triggering schema reload while concurrent LDAP queries are active can cause use-after-free and crash ns-slapd. Red Hat assigns AC:H and PR:H because the race window is nanoseconds-wide and stress testing did not produce a natural crash; schema reload requires administrative privileges. Schedule schema reloads during maintenance windows with reduced LDAP traffic.

Меры по смягчению последствий

Schedule schema reload operations during maintenance windows with reduced LDAP traffic. Minimize schema reload frequency; in replication topologies schema changes propagate automatically. Monitor for unexpected ns-slapd restarts during or immediately after schema reloads. Restrict write access to cn=schema,cn=config to dedicated administrative accounts via LDAP ACIs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseFix deferred
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2485414389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()

EPSS

Процентиль: 12%
0.00212
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

CVSS3: 5
nvd
2 месяца назад

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

CVSS3: 5
debian
2 месяца назад

A flaw was found in 389 Directory Server. During schema reload, the at ...

CVSS3: 5
github
2 месяца назад

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 12%
0.00212
Низкий

5 Medium

CVSS3