在 389 Directory Server(389-ds-base)的 SASL I/O 层中,发现了一个堆缓冲区溢出漏洞。 在 函数中,从网络读取的封装记录长度仅根据上限进行校验。当接收到极小的网络长度值(0、1 或 2)时,会导致 小于已消耗的 ,从而在 中引发无符号整数减法下溢。随后,系统会请求 将大约 4 GiB 的数据读取到一个仅 1024 字节的堆缓冲区中,导致堆缓冲区溢出,且溢出内容由攻击者控制。 在完成带有完整性保护(SSF > 0)的 SASL 绑定后,经过身份验证的远程攻击者可利用此缺陷造成服
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 11 | any |
affected |
| Red Hat | Red Hat Directory Server 12 | any |
affected |
| Red Hat | Red Hat Directory Server 13 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | 8080020260903102346.f969626e ~ * |
cpe:/a:redhat:directory_server_e4s:11.7::el8
|
|
| Red Hat | Red Hat Directory Server 11.9 for RHEL 8 | 8100020260904171440.37ed7c03 ~ * |
cpe:/a:redhat:directory_server:11.9::el8
|
|
| Red Hat | Red Hat Directory Server 12.2 E4S for RHEL 9 | 9020020260903155914.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.2::el9
|
|
| Red Hat | Red Hat Directory Server 12.4 E4S for RHEL 9 | 9040020260903102623.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.4::el9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.2.0-10.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.0.6-21.el10_0 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.3.11.1-15.el7_9 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 8100020260904155442.25e700aa ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020260901171549.96015a92 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 8040020260901171549.96015a92 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 8060020260901145727.824efc52 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 8060020260901145727.824efc52 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 8080020260831180218.6dbb3803 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 8080020260831180218.6dbb3803 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.8.0-10.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:2.2.4-22.el9_2 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:2.4.5-29.el9_4 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:2.6.1-24.el9_6 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat Directory Server 12 | - |
cpe:/a:redhat:directory_server:12
|
|
| Red Hat | Red Hat Directory Server 13 | - |
cpe:/a:redhat:directory_server:13
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18922 | 9.8 CRITICAL | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo |
| CVE-2026-76578 | 9.8 CRITICAL | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi |
| CVE-2026-86404 | 8.8 HIGH | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging- |
| CVE-2026-19843 | 8.4 HIGH | 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console l |
| CVE-2026-79678 | 8.1 HIGH | Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm |
| CVE-2026-18453 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an |
| CVE-2026-76560 | 7.5 HIGH | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt |
| CVE-2026-86332 | 6.5 MEDIUM | Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user |
| CVE-2026-86469 | 5.3 MEDIUM | Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path |
No comments yet