Bug 2484414 (CVE-2026-11610)
| Summary: | CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aadhikar, bsmejkal, jachapma, mreynolds, progier, rhel-process-autobot, security-response-team, snegrini, spichugi, tbordaz, vashirov, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server
(389-ds-base). After a successful SASL bind with integrity protection (SSF > 0),
an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet
that is copied into a 512-byte heap receive buffer without a bounds check in
sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of
attacker-controlled data to overflow the buffer, causing a denial of service (server
crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with
a valid Kerberos ticket, any enrolled host, or any service account can trigger this
vulnerability over the network after authenticating via GSSAPI.
The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and
was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow
in schema.c only.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2497652 | ||
| Bug Blocks: | |||
| Deadline: | 2026-07-07 | ||
|
Description
OSIDB Bzimport
2026-06-03 15:59:33 UTC
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:36200 https://access.redhat.com/errata/RHSA-2026:36200 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:36197 https://access.redhat.com/errata/RHSA-2026:36197 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:36198 https://access.redhat.com/errata/RHSA-2026:36198 This issue has been addressed in the following products: Red Hat Directory Server 11.5 E4S for RHEL 8 Via RHSA-2026:36204 https://access.redhat.com/errata/RHSA-2026:36204 This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:36208 https://access.redhat.com/errata/RHSA-2026:36208 This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:36209 https://access.redhat.com/errata/RHSA-2026:36209 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:36195 https://access.redhat.com/errata/RHSA-2026:36195 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:36196 https://access.redhat.com/errata/RHSA-2026:36196 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:36206 https://access.redhat.com/errata/RHSA-2026:36206 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:36205 https://access.redhat.com/errata/RHSA-2026:36205 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:36202 https://access.redhat.com/errata/RHSA-2026:36202 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:36201 https://access.redhat.com/errata/RHSA-2026:36201 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:36585 https://access.redhat.com/errata/RHSA-2026:36585 This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:36641 https://access.redhat.com/errata/RHSA-2026:36641 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:36670 https://access.redhat.com/errata/RHSA-2026:36670 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:36671 https://access.redhat.com/errata/RHSA-2026:36671 |