CVE-2026-11774: Red Hat Directory Server 11.5 e4s For Rhel 8
High severity, CVSS 7.6. EPSS: 0.7% chance of exploitation in the next 30 days.
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
Affected products
- Red Hat Red Hat Directory Server 11.5 e4s For Rhel 8: before 8060020260702180044.0ca98e7e (fixed in 8060020260702180044.0ca98e7e)
- Red Hat Red Hat Directory Server 11.7 e4s For Rhel 8: before 8080020260702180836.f969626e (fixed in 8080020260702180836.f969626e)
- Red Hat Red Hat Directory Server 11.9 For Rhel 8: before 8100020260702145313.37ed7c03 (fixed in 8100020260702145313.37ed7c03)
- Red Hat Red Hat Directory Server 12
- Red Hat Red Hat Directory Server 12.2 e4s For Rhel 9: before 9020020260703060155.1674d574 (fixed in 9020020260703060155.1674d574)
- Red Hat Red Hat Directory Server 12.4 e4s For Rhel 9: before 9040020260703055735.1674d574 (fixed in 9040020260703055735.1674d574)
- Red Hat Red Hat Directory Server 13
- Red Hat Red Hat Directory Server 13.2: before 1783452100 (fixed in 1783452100)
- Red Hat Red Hat Enterprise Linux 10: before 0:3.2.0-8.el10_2 (fixed in 0:3.2.0-8.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.0.6-19.el10_0 (fixed in 0:3.0.6-19.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.3.11.1-13.el7_9 (fixed in 0:1.3.11.1-13.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 8100020260626120929.25e700aa (fixed in 8100020260626120929.25e700aa)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 8040020260629123121.96015a92 (fixed in 8040020260629123121.96015a92)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 8040020260629123121.96015a92 (fixed in 8040020260629123121.96015a92)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020260626130540.824efc52 (fixed in 8060020260626130540.824efc52)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 8060020260626130540.824efc52 (fixed in 8060020260626130540.824efc52)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 8080020260630025241.6dbb3803 (fixed in 8080020260630025241.6dbb3803)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 8080020260630025241.6dbb3803 (fixed in 8080020260630025241.6dbb3803)
- Red Hat Red Hat Enterprise Linux 9: before 0:2.8.0-8.el9_8 (fixed in 0:2.8.0-8.el9_8)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.2.4-19.el9_2 (fixed in 0:2.2.4-19.el9_2)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:2.4.5-26.el9_4 (fixed in 0:2.4.5-26.el9_4)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:2.6.1-22.el9_6 (fixed in 0:2.6.1-22.el9_6)
Published 2026-06-11. Last modified 2026-07-15.