Bug 2510684 - CVE-2026-18651 389-ds-base: 389-ds-base: SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account [fedora-all]
Summary: CVE-2026-18651 389-ds-base: 389-ds-base: SASL PLAIN bind installs connection ...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: 389-ds-base
Version: 45
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: mreynolds
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["c1b958d2-0f90-4af1-ad02-d...
Depends On:
Blocks: CVE-2026-18651
TreeView+ depends on / blocked
 
Reported: 2026-08-03 14:49 UTC by mkaminsk
Modified: 2026-08-17 15:45 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)

Description mkaminsk 2026-08-03 14:49:02 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in 389 Directory Server (389-ds-base). In ids_sasl_check_bind(), on a successful SASL_OK from the underlying Cyrus SASL library, the connection is marked SASL-complete and bind credentials are installed via bind_credentials_set_nolock() before the account-lock check (slapi_check_account_lock()) is performed for non-root binds. If the subsequent lock check determines the account is locked (nsAccountLock: true), the bind is failed and reported to the client, but the already-installed SASL-complete flag and bind credentials are not reverted. A client that already knows the correct password for an account that has since been administratively locked can bind via SASL PLAIN, receive an "account locked" failure response, and continue using the same, already-authenticated TCP connection to perform further LDAP operations as that account -- defeating account lock as an access-revocation control. Setting nsslapd-close-on-failed-bind does not mitigate this. This finding was independently reported by two unrelated parties (OpenAI Security Research and Andrew Rukin of Arenadata) who converged on the identical root cause.

Comment 1 Aoife Moloney 2026-08-17 15:45:46 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.


Note You need to log in before you can comment on or make changes to this bug.