<Vulnerability name="CVE-2026-11610">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-07T09:00:00</PublicDate>
    <Bugzilla id="2484414" url="https://bugzilla.redhat.com/show_bug.cgi?id=2484414" xml:lang="en:us">
389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-122</CWE>
    <Details xml:lang="en:us" source="Mitre">
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server
(389-ds-base). After a successful SASL bind with integrity protection (SSF &gt; 0),
an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet
that is copied into a 512-byte heap receive buffer without a bounds check in
sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of
attacker-controlled data to overflow the buffer, causing a denial of service (server
crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with
a valid Kerberos ticket, any enrolled host, or any service account can trigger this
vulnerability over the network after authenticating via GSSAPI.
The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and
was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow
in schema.c only.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server
(389-ds-base). After a successful SASL bind with integrity protection (SSF &gt; 0),
an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet
that is copied into a 512-byte heap receive buffer without a bounds check in
sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of
attacker-controlled data to overflow the buffer, causing a denial of service (server
crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with
a valid Kerberos ticket, any enrolled host, or any service account can trigger this
vulnerability over the network after authenticating via GSSAPI.
The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and
was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow
in schema.c only.
    </Details>
    <Statement xml:lang="en:us">
Red Hat rates this issue as Important impact. After a successful SASL bind with integrity protection (SSF &gt; 0), an authenticated remote attacker can send a crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv(). Up to roughly two megabytes of attacker-controlled data can overflow the buffer, reliably crashing ns-slapd on production builds. Exploitation requires a valid SASL-authenticated LDAP session, not Directory Manager access. Any user who can bind with SASL mechanisms such as GSSAPI/Kerberos or DIGEST-MD5 can trigger the denial of service. In deployments where domain users, enrolled hosts, and service accounts routinely authenticate to the directory over Kerberos, the attack surface includes any such principal with network access to LDAP. This flaw is independent of CVE-2025-14905, which patched a separate heap overflow in schema.c and did not modify sasl_io.c.
    </Statement>
    <Acknowledgement xml:lang="en:us">
This issue was discovered by Ian Murphy (Red Hat).
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
There is no complete workaround for this flaw.
Mitigations that reduce exposure:
1. Restrict network access to LDAP ports (389/636) to trusted networks only.
   Note: In FreeIPA/IdM deployments, enrolled clients require LDAP access and
   this may not be practical.
2. If DIGEST-MD5 is not required, disable it via nsslapd-allowed-sasl-mechanisms
   in cn=config. GSSAPI/Kerberos cannot be disabled in FreeIPA/IdM without breaking
   domain authentication.
3. Monitor for oversized LDAP UNBIND packets (standard UNBIND is 7 bytes; alert on
   UNBIND packets exceeding ~100 bytes).
4. Lowering nsslapd-maxbersize reduces maximum overflow size but does not eliminate
   the vulnerability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server_e4s:11.5::el8">
        <ProductName>Red Hat Directory Server 11.5 E4S for RHEL 8</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36204">RHSA-2026:36204</Advisory>
        <Package name="redhat-ds:11">redhat-ds:11-8060020260702180044.0ca98e7e</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server_e4s:11.7::el8">
        <ProductName>Red Hat Directory Server 11.7 E4S for RHEL 8</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36208">RHSA-2026:36208</Advisory>
        <Package name="redhat-ds:11">redhat-ds:11-8080020260702180836.f969626e</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server:11.9::el8">
        <ProductName>Red Hat Directory Server 11.9 for RHEL 8</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36200">RHSA-2026:36200</Advisory>
        <Package name="redhat-ds:11">redhat-ds:11-8100020260702145313.37ed7c03</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server_e4s:12.2::el9">
        <ProductName>Red Hat Directory Server 12.2 E4S for RHEL 9</ProductName>
        <ReleaseDate>2026-07-08T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36641">RHSA-2026:36641</Advisory>
        <Package name="redhat-ds:12">redhat-ds:12-9020020260703060155.1674d574</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server_e4s:12.4::el9">
        <ProductName>Red Hat Directory Server 12.4 E4S for RHEL 9</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36209">RHSA-2026:36209</Advisory>
        <Package name="redhat-ds:12">redhat-ds:12-9040020260703055735.1674d574</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36196">RHSA-2026:36196</Advisory>
        <Package name="389-ds-base">389-ds-base-0:3.2.0-8.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-07-08T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36670">RHSA-2026:36670</Advisory>
        <Package name="389-ds-base">389-ds-base-0:3.0.6-19.el10_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_els:7">
        <ProductName>Red Hat Enterprise Linux 7 Extended Lifecycle Support</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36205">RHSA-2026:36205</Advisory>
        <Package name="389-ds-base">389-ds-base-0:1.3.11.1-13.el7_9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36201">RHSA-2026:36201</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8100020260626120929.25e700aa</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_aus:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36206">RHSA-2026:36206</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8040020260629123121.96015a92</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus_long_life:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36206">RHSA-2026:36206</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8040020260629123121.96015a92</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_aus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36202">RHSA-2026:36202</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8060020260626130540.824efc52</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus_long_life:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36202">RHSA-2026:36202</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8060020260626130540.824efc52</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_tus:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36197">RHSA-2026:36197</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8080020260630025241.6dbb3803</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36197">RHSA-2026:36197</Advisory>
        <Package name="389-ds:1.4">389-ds:1.4-8080020260630025241.6dbb3803</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36195">RHSA-2026:36195</Advisory>
        <Package name="389-ds-base">389-ds-base-0:2.8.0-8.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-07-08T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36585">RHSA-2026:36585</Advisory>
        <Package name="389-ds-base">389-ds-base-0:2.2.4-19.el9_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-07-07T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36198">RHSA-2026:36198</Advisory>
        <Package name="389-ds-base">389-ds-base-0:2.4.5-26.el9_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-07-08T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36671">RHSA-2026:36671</Advisory>
        <Package name="389-ds-base">389-ds-base-0:2.6.1-22.el9_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:directory_server:13.2::el10">
        <ProductName>Red Hat Directory Server 13.2</ProductName>
        <ReleaseDate>2026-07-08T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:36660">RHSA-2026:36660</Advisory>
        <Package name="dirsrv/dirsrv-container-rhel10">dirsrv/dirsrv-container-rhel10:1783452100</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:directory_server:12">
        <ProductName>Red Hat Directory Server 12</ProductName>
        <FixState>Affected</FixState>
        <PackageName>redhat-ds:12/389-ds-base</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:directory_server:13">
        <ProductName>Red Hat Directory Server 13</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>389-ds-base</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>389-ds-base</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-11610
https://nvd.nist.gov/vuln/detail/CVE-2026-11610
    </References>
</Vulnerability>