CVE-2026-11610
389ds 389-ds-base, Red Hat Directory Server 11.5 E4S for RHEL 8, Red Hat Directory Server 11.7 E4S for RHEL 8
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket,...
- CVSS
- 8.8
- EPSS
- 0.63% 46.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07