在 FreeIPA 的 命令中发现了一个缺陷:对 或 输入进行校验不足,导致这些输入在进入受限的 调用时,尚未执行相应的 LDAP 访问控制检查。这使得任意已认证的 IPA 主体(无论其权限级别如何)都能枚举并读取受影响的服务器进程的环境变量,并可通过内存耗尽导致服务拒绝(Denial of Service, DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18922 | 9.8 CRITICAL | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo |
| CVE-2026-76578 | 9.8 CRITICAL | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi |
| CVE-2026-86404 | 8.8 HIGH | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging- |
| CVE-2026-19843 | 8.4 HIGH | 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console l |
| CVE-2026-18453 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an |
| CVE-2026-18355 | 7.5 HIGH | 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound |
| CVE-2026-76560 | 7.5 HIGH | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt |
| CVE-2026-86332 | 6.5 MEDIUM | Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user |
| CVE-2026-86469 | 5.3 MEDIUM | Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path |
No comments yet