Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in 389 Directory Server (389-ds-base). During SASL PLAIN authentication, the ids_sasl_canon_user() function writes the resolved bind DN into a Cyrus SASL auxiliary property (prop_set) on every canonicalization attempt, including failed ones. A failed one-shot PLAIN exchange does not trigger SASL-context recreation in ids_sasl_check_bind() -- that only happens when CONN_FLAG_SASL_COMPLETE or continuing is already set. A subsequent successful SASL bind on the same connection retrieves the auxiliary property via prop_getnames() and unconditionally trusts only the first stored value (dnval[0].values[0]), with no check on which SASL mechanism completed the second exchange and no check that the value corresponds to the identity actually just authenticated. An unprivileged remote attacker can exploit this with zero valid credentials: first send a SASL PLAIN bind as cn=Directory Manager with an incorrect password (fails as expected, but leaves the Directory Manager DN in slot 0 of the auxiliary property), then complete a SASL ANONYMOUS bind on the same connection. The server installs the stale Directory Manager identity instead of the anonymous identity, granting full Directory Manager authority. This was independently confirmed by Red Hat Product Security in an isolated, network-disconnected sandbox against 389-ds-base-2.9.0: "Who Am I?" returned "cn=directory manager", and the Directory-Manager-only cn=config attribute nsslapd-rootdn became readable. The same stale-identity mechanism also allows escalation via a valid low-privileged account's own successful second bind (originally reported variant, requiring one valid account), independently reproduced against the reporter's own PoC. Root cause: ldap/servers/slapd/saslbind.c, ids_sasl_canon_user() (identity write, unconditional per mechanism) and ids_sasl_check_bind() (identity read-back and installation, no mechanism check, no freshness check). Verified directly against commit 33c0e0115c03017ba94ee02f144383704de32a25; unchanged since a September 2024 logging-format cleanup.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:64771 https://access.redhat.com/errata/RHSA-2026:64771
This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:64779 https://access.redhat.com/errata/RHSA-2026:64779
This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:64780 https://access.redhat.com/errata/RHSA-2026:64780
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:64776 https://access.redhat.com/errata/RHSA-2026:64776
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:64778 https://access.redhat.com/errata/RHSA-2026:64778
This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:64792 https://access.redhat.com/errata/RHSA-2026:64792
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:64781 https://access.redhat.com/errata/RHSA-2026:64781
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:64793 https://access.redhat.com/errata/RHSA-2026:64793
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:64789 https://access.redhat.com/errata/RHSA-2026:64789
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:64790 https://access.redhat.com/errata/RHSA-2026:64790
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2026:64811 https://access.redhat.com/errata/RHSA-2026:64811
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:64783 https://access.redhat.com/errata/RHSA-2026:64783
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:64804 https://access.redhat.com/errata/RHSA-2026:64804
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:64791 https://access.redhat.com/errata/RHSA-2026:64791
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:64785 https://access.redhat.com/errata/RHSA-2026:64785
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:64784 https://access.redhat.com/errata/RHSA-2026:64784