Fedora Account System
Red Hat Associate
Red Hat Customer
An integer overflow in the 389 Directory Server SASL I/O layer allows any SASL-authenticated user to bypass the nsslapd-maxsasliosize packet size limit and crash the LDAP server, with potential code execution on older platforms (RCE demonstrated on RHEL 8 via tcache poisoning). After authenticating with Kerberos or DIGEST-MD5, an attacker sends a SASL-framed packet with a crafted 4-byte length prefix of 0xFFFFFFFC. In sasl_io_start_packet() (sasl_io.c:372-374), packet_length += sizeof(uint32_t) wraps to 0, bypassing the size limit check. sasl_io_read_packet() then computes bytes_remaining underflow, and NSPR passes a near-maximum recv() size into a 1024-byte encrypted_buffer — a controlled heap buffer overflow of up to maxbersize (~2MB). In FreeIPA/IdM deployments, any domain user with a Kerberos ticket, enrolled host, or service account can trigger this remotely. Introduced when the SASL I/O layer was first added to 389-ds-base. Independent of Finding 008 (different code path in same file). CVE-2025-14905 fix patched schema.c only; sasl_io.c untouched. DoS confirmed on Fedora 42 (GDB-verified) and RHEL 8 production binary. RCE demonstrated on RHEL 8 (glibc 2.28) via tcache poisoning; blocked on glibc 2.32+ by safe linking.
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:36200 https://access.redhat.com/errata/RHSA-2026:36200
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:36197 https://access.redhat.com/errata/RHSA-2026:36197
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:36198 https://access.redhat.com/errata/RHSA-2026:36198
This issue has been addressed in the following products: Red Hat Directory Server 11.5 E4S for RHEL 8 Via RHSA-2026:36204 https://access.redhat.com/errata/RHSA-2026:36204
This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:36208 https://access.redhat.com/errata/RHSA-2026:36208
This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:36209 https://access.redhat.com/errata/RHSA-2026:36209
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:36195 https://access.redhat.com/errata/RHSA-2026:36195
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:36196 https://access.redhat.com/errata/RHSA-2026:36196
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:36206 https://access.redhat.com/errata/RHSA-2026:36206
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:36205 https://access.redhat.com/errata/RHSA-2026:36205
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:36202 https://access.redhat.com/errata/RHSA-2026:36202
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:36201 https://access.redhat.com/errata/RHSA-2026:36201
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:36585 https://access.redhat.com/errata/RHSA-2026:36585
This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:36641 https://access.redhat.com/errata/RHSA-2026:36641
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:36670 https://access.redhat.com/errata/RHSA-2026:36670
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:36671 https://access.redhat.com/errata/RHSA-2026:36671