Bug 2484414 (CVE-2026-11610)

Summary: CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aadhikar, bsmejkal, jachapma, mreynolds, progier, rhel-process-autobot, security-response-team, snegrini, spichugi, tbordaz, vashirov, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2497652    
Bug Blocks:    
Deadline: 2026-07-07   

Description OSIDB Bzimport 2026-06-03 15:59:33 UTC
Finding 008 — 389-ds-base SASL heap overflow in sasl_io_recv().

Vulnerable: ldap/servers/slapd/sasl_io.c (~line 456), SASL_IO_BUFFER_NOT_ENCRYPTED path.
Introduced by commit b4cdebbe (~2013). Missing bounds check on memcpy into 512-byte c_buffer.

Trigger: SASL bind (GSSAPI/DIGEST-MD5), then send padded raw LDAP UNBIND.
DoS confirmed on production binary (389-ds-base-3.1.4-6.fc42).

Fix: add bounds check before memcpy, same pattern as encrypted return path in sasl_io_recv().

Comment 1 errata-xmlrpc 2026-07-07 11:57:36 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.9 for RHEL 8

Via RHSA-2026:36200 https://access.redhat.com/errata/RHSA-2026:36200

Comment 2 errata-xmlrpc 2026-07-07 12:20:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:36197 https://access.redhat.com/errata/RHSA-2026:36197

Comment 3 errata-xmlrpc 2026-07-07 12:23:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:36198 https://access.redhat.com/errata/RHSA-2026:36198

Comment 4 errata-xmlrpc 2026-07-07 12:27:10 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.5 E4S for RHEL 8

Via RHSA-2026:36204 https://access.redhat.com/errata/RHSA-2026:36204

Comment 5 errata-xmlrpc 2026-07-07 12:30:20 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.7 E4S for RHEL 8

Via RHSA-2026:36208 https://access.redhat.com/errata/RHSA-2026:36208

Comment 6 errata-xmlrpc 2026-07-07 12:30:28 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 12.4 E4S for RHEL 9

Via RHSA-2026:36209 https://access.redhat.com/errata/RHSA-2026:36209

Comment 7 errata-xmlrpc 2026-07-07 12:40:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:36195 https://access.redhat.com/errata/RHSA-2026:36195

Comment 8 errata-xmlrpc 2026-07-07 12:46:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:36196 https://access.redhat.com/errata/RHSA-2026:36196

Comment 9 errata-xmlrpc 2026-07-07 13:01:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:36206 https://access.redhat.com/errata/RHSA-2026:36206

Comment 10 errata-xmlrpc 2026-07-07 13:01:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:36205 https://access.redhat.com/errata/RHSA-2026:36205

Comment 11 errata-xmlrpc 2026-07-07 13:21:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:36202 https://access.redhat.com/errata/RHSA-2026:36202

Comment 12 errata-xmlrpc 2026-07-07 13:25:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:36201 https://access.redhat.com/errata/RHSA-2026:36201

Comment 13 errata-xmlrpc 2026-07-08 06:26:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:36585 https://access.redhat.com/errata/RHSA-2026:36585

Comment 14 errata-xmlrpc 2026-07-08 09:24:19 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 12.2 E4S for RHEL 9

Via RHSA-2026:36641 https://access.redhat.com/errata/RHSA-2026:36641

Comment 15 errata-xmlrpc 2026-07-08 11:28:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:36670 https://access.redhat.com/errata/RHSA-2026:36670

Comment 16 errata-xmlrpc 2026-07-08 12:11:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:36671 https://access.redhat.com/errata/RHSA-2026:36671