Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in ldap/servers/plugins/replication/repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer (ridbuff[RIDSTR_SIZE]) without bounds checking the loop counter. A remote unauthenticated attacker can crash the ns-slapd process by sending a crafted StartNSDS50ReplicationRequest LDAP extended operation (OID 2.16.840.1.113730.3.5.12) containing more than 16 consecutive digit characters in the replica ID field. The overflow occurs during payload decoding in decode_startrepl_extop(), before the replica_is_updatedn() authorization check runs, making it exploitable without credentials on default configurations where anonymous access is enabled. On production builds with stack protectors, the impact is limited to denial of service (process abort). The vulnerable code path is: decode_startrepl_extop() -> decode_ruv() -> ruv_init_from_bervals() -> get_ruvelement_from_berval().
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:55421 https://access.redhat.com/errata/RHSA-2026:55421
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55425 https://access.redhat.com/errata/RHSA-2026:55425
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:55422 https://access.redhat.com/errata/RHSA-2026:55422
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:55426 https://access.redhat.com/errata/RHSA-2026:55426
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55424 https://access.redhat.com/errata/RHSA-2026:55424
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55423 https://access.redhat.com/errata/RHSA-2026:55423
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:55532 https://access.redhat.com/errata/RHSA-2026:55532
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:55530 https://access.redhat.com/errata/RHSA-2026:55530
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:55757 https://access.redhat.com/errata/RHSA-2026:55757
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:55756 https://access.redhat.com/errata/RHSA-2026:55756
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:55758 https://access.redhat.com/errata/RHSA-2026:55758
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:55794 https://access.redhat.com/errata/RHSA-2026:55794
This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:56047 https://access.redhat.com/errata/RHSA-2026:56047
This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:56048 https://access.redhat.com/errata/RHSA-2026:56048
This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:56050 https://access.redhat.com/errata/RHSA-2026:56050