CVE-2026-11610: 389ds 389-Ds-Base

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

Affected products

  • 389ds 389-Ds-Base: from 1.3.2, up to and including 3.3.0
  • Red Hat Red Hat Directory Server 11.5 e4s For Rhel 8: before 8060020260702180044.0ca98e7e (fixed in 8060020260702180044.0ca98e7e)
  • Red Hat Red Hat Directory Server 11.7 e4s For Rhel 8: before 8080020260702180836.f969626e (fixed in 8080020260702180836.f969626e)
  • Red Hat Red Hat Directory Server 11.9 For Rhel 8: before 8100020260702145313.37ed7c03 (fixed in 8100020260702145313.37ed7c03)
  • Red Hat Red Hat Directory Server 12
  • Red Hat Red Hat Directory Server 12.2 e4s For Rhel 9: before 9020020260703060155.1674d574 (fixed in 9020020260703060155.1674d574)
  • Red Hat Red Hat Directory Server 12.4 e4s For Rhel 9: before 9040020260703055735.1674d574 (fixed in 9040020260703055735.1674d574)
  • Red Hat Red Hat Directory Server 13
  • Red Hat Red Hat Directory Server 13.2: before 1783452100 (fixed in 1783452100)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.2.0-8.el10_2 (fixed in 0:3.2.0-8.el10_2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.0.6-19.el10_0 (fixed in 0:3.0.6-19.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.3.11.1-13.el7_9 (fixed in 0:1.3.11.1-13.el7_9)
  • Red Hat Red Hat Enterprise Linux 8: before 8100020260626120929.25e700aa (fixed in 8100020260626120929.25e700aa)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 8040020260629123121.96015a92 (fixed in 8040020260629123121.96015a92)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 8040020260629123121.96015a92 (fixed in 8040020260629123121.96015a92)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020260626130540.824efc52 (fixed in 8060020260626130540.824efc52)
  • Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 8060020260626130540.824efc52 (fixed in 8060020260626130540.824efc52)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 8080020260630025241.6dbb3803 (fixed in 8080020260630025241.6dbb3803)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 8080020260630025241.6dbb3803 (fixed in 8080020260630025241.6dbb3803)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.8.0-8.el9_8 (fixed in 0:2.8.0-8.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.2.4-19.el9_2 (fixed in 0:2.2.4-19.el9_2)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:2.4.5-26.el9_4 (fixed in 0:2.4.5-26.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:2.6.1-22.el9_6 (fixed in 0:2.6.1-22.el9_6)

Published 2026-07-07. Last modified 2026-07-08.