目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-18355— 389-ds-base: sasl_io_start_packet 堆缓冲区溢出漏洞

一分钟漏洞结论

影响对象
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 389 Directory Server(389-ds-base)的 SASL I/O 层中,发现了一个堆缓冲区溢出漏洞。 在 函数中,从网络读取的封装记录长度仅根据上限进行校验。当接收到极小的网络长度值(0、1 或 2)时,会导致 小于已消耗的 ,从而在 中引发无符号整数减法下溢。随后,系统会请求 将大约 4 GiB 的数据读取到一个仅 1024 字节的堆缓冲区中,导致堆缓冲区溢出,且溢出内容由攻击者控制。 在完成带有完整性保护(SSF > 0)的 SASL 绑定后,经过身份验证的远程攻击者可利用此缺陷造成服

CVSS 7.5 · High

可能的 ATT&CK 技术 1 AI

T1210 · Exploitation of Remote Services

影响版本矩阵 8

厂商产品 版本范围状态
Red Hat Red Hat Directory Server 11 全部 affected
Red Hat Red Hat Directory Server 12 全部 affected
Red Hat Red Hat Directory Server 13 全部 unaffected
Red Hat Red Hat Enterprise Linux 10 全部 affected
Red Hat Red Hat Enterprise Linux 6 全部 unaffected
Red Hat Red Hat Enterprise Linux 7 全部 affected
Red Hat Red Hat Enterprise Linux 8 全部 affected
Red Hat Red Hat Enterprise Linux 9 全部 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-18355 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()
来源: CVE Program / CVE List V5
Vulnerability Description
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
整数下溢(超界折返)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260903102346.f969626e ~ * cpe:/a:redhat:directory_server_e4s:11.7::el8
Red Hat Red Hat Directory Server 11.9 for RHEL 8 8100020260904171440.37ed7c03 ~ * cpe:/a:redhat:directory_server:11.9::el8
Red Hat Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260903155914.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.2::el9
Red Hat Red Hat Directory Server 12.4 E4S for RHEL 9 9040020260903102623.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.4::el9
Red Hat Red Hat Enterprise Linux 10 0:3.2.0-10.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.0.6-21.el10_0 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.3.11.1-15.el7_9 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 8100020260904155442.25e700aa ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020260901171549.96015a92 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 8040020260901171549.96015a92 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 8060020260901145727.824efc52 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 8060020260901145727.824efc52 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 8080020260831180218.6dbb3803 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 8080020260831180218.6dbb3803 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 9 0:2.8.0-10.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.2.4-22.el9_2 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.4.5-29.el9_4 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.6.1-24.el9_6 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Directory Server 13 - cpe:/a:redhat:directory_server:13
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6

二、漏洞 CVE-2026-18355 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-18355 的情报信息

登录查看更多情报信息。

CVE-2026-18355 厂商安全公告 (2)

CVE-2026-18355 其他参考 (15)

同批安全公告 · Red Hat · 2026-09-07 · 共 10 条

CVE-2026-18922 9.8 CRITICAL 389-ds-base 权限提升漏洞
CVE-2026-76578 9.8 CRITICAL FreeIPA 未认证LDAP客户端获取管理员凭据漏洞
CVE-2026-86404 8.8 HIGH Red Hat EAP 7.0 Artemis 默认反序列化漏洞
CVE-2026-19843 8.4 HIGH 389-ds-base 389控制台LDAP编辑器命令注入漏洞
CVE-2026-79678 8.1 HIGH FreeIPA idm: idp-add 未授权代码执行与拒绝服务
CVE-2026-18453 7.5 HIGH 389-ds-base 预认证空指针解引用漏洞
CVE-2026-76560 7.5 HIGH 389-ds 匿名LDAP客户端空DN绕过ACL绑定检查
CVE-2026-86332 6.5 MEDIUM ODH Dashboard: nim凭据密钥任意认证用户可读漏洞
CVE-2026-86469 5.3 MEDIUM GLib2 2.74.0 符号链接竞争条件漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-18355

暂无评论


发表评论