CVE-2026-16560: Red Hat Directory Server 11
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.
Affected products
- Red Hat Red Hat Directory Server 11
- Red Hat Red Hat Directory Server 12
- Red Hat Red Hat Directory Server 13
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
Published 2026-07-22. Last modified 2026-07-22.