Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-11774

PUBLISHED 15.07.2026

CNA: redhat

389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow

Обновлено: 08.07.2026
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.

CWE

Идентификатор Описание
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CVSS

Оценка Severity Версия Базовый вектор
7.6 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Доп. Информация

Product Status

Red Hat Directory Server 11.5 E4S for RHEL 8
Product: Red Hat Directory Server 11.5 E4S for RHEL 8
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8060020260702180044.0ca98e7e до * unaffected
СPE:
  • cpe:/a:redhat:directory_server_e4s:11.5::el8
Red Hat Directory Server 11.7 E4S for RHEL 8
Product: Red Hat Directory Server 11.7 E4S for RHEL 8
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8080020260702180836.f969626e до * unaffected
СPE:
  • cpe:/a:redhat:directory_server_e4s:11.7::el8
Red Hat Directory Server 11.9 for RHEL 8
Product: Red Hat Directory Server 11.9 for RHEL 8
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8100020260702145313.37ed7c03 до * unaffected
СPE:
  • cpe:/a:redhat:directory_server:11.9::el8
Red Hat Directory Server 12.2 E4S for RHEL 9
Product: Red Hat Directory Server 12.2 E4S for RHEL 9
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 9020020260703060155.1674d574 до * unaffected
СPE:
  • cpe:/a:redhat:directory_server_e4s:12.2::el9
Red Hat Directory Server 12.4 E4S for RHEL 9
Product: Red Hat Directory Server 12.4 E4S for RHEL 9
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 9040020260703055735.1674d574 до * unaffected
СPE:
  • cpe:/a:redhat:directory_server_e4s:12.4::el9
Red Hat Enterprise Linux 10
Product: Red Hat Enterprise Linux 10
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:3.2.0-8.el10_2 до * unaffected
СPE:
  • cpe:/o:redhat:enterprise_linux:10.2
Red Hat Enterprise Linux 10.0 Extended Update Support
Product: Red Hat Enterprise Linux 10.0 Extended Update Support
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:3.0.6-19.el10_0 до * unaffected
СPE:
  • cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Product: Red Hat Enterprise Linux 7 Extended Lifecycle Support
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:1.3.11.1-13.el7_9 до * unaffected
СPE:
  • cpe:/o:redhat:rhel_els:7
Red Hat Enterprise Linux 8
Product: Red Hat Enterprise Linux 8
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8100020260626120929.25e700aa до * unaffected
СPE:
  • cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8040020260629123121.96015a92 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_aus:8.4::appstream
  • cpe:/a:redhat:rhel_eus_long_life:8.4::appstream
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8040020260629123121.96015a92 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_aus:8.4::appstream
  • cpe:/a:redhat:rhel_eus_long_life:8.4::appstream
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8060020260626130540.824efc52 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_aus:8.6::appstream
  • cpe:/a:redhat:rhel_eus_long_life:8.6::appstream
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Product: Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8060020260626130540.824efc52 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_aus:8.6::appstream
  • cpe:/a:redhat:rhel_eus_long_life:8.6::appstream
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8080020260630025241.6dbb3803 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_e4s:8.8::appstream
  • cpe:/a:redhat:rhel_tus:8.8::appstream
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8080020260630025241.6dbb3803 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_e4s:8.8::appstream
  • cpe:/a:redhat:rhel_tus:8.8::appstream
Red Hat Enterprise Linux 9
Product: Red Hat Enterprise Linux 9
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:2.8.0-8.el9_8 до * unaffected
СPE:
  • cpe:/a:redhat:enterprise_linux:9::appstream
  • cpe:/a:redhat:enterprise_linux:9::crb
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:2.2.4-19.el9_2 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Product: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:2.4.5-26.el9_4 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Enterprise Linux 9.6 Extended Update Support
Product: Red Hat Enterprise Linux 9.6 Extended Update Support
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0:2.6.1-22.el9_6 до * unaffected
СPE:
  • cpe:/a:redhat:rhel_eus:9.6::appstream
  • cpe:/a:redhat:rhel_eus:9.6::crb
Red Hat Directory Server 13.2
Product: Red Hat Directory Server 13.2
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1783452100 до * unaffected
СPE:
  • cpe:/a:redhat:directory_server:13.2::el10
Red Hat Directory Server 12
Product: Red Hat Directory Server 12
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:directory_server:12
Red Hat Directory Server 13
Product: Red Hat Directory Server 13
Vendor: Red Hat
Default status: unaffected
СPE:
  • cpe:/a:redhat:directory_server:13
Red Hat Enterprise Linux 6
Product: Red Hat Enterprise Linux 6
Vendor: Red Hat
Default status: unaffected
СPE:
  • cpe:/o:redhat:enterprise_linux:6
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 12.06.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no partial 2.0.3 12.06.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.