Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15041

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

Меры по смягчению последствий

If possible, configure 389 Directory Server to use an alternative password storage scheme (e.g., SSHA512 or GOST-Yescrypt) which uses constant-time comparison.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseFix deferred
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2498022389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification

EPSS

Процентиль: 23%
0.003
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

CVSS3: 3.7
nvd
около 1 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

CVSS3: 3.7
debian
около 1 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password v ...

CVSS3: 3.7
github
около 1 месяца назад

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

EPSS

Процентиль: 23%
0.003
Низкий

3.7 Low

CVSS3