389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.6epss 0.8%
probabilidade de exploração
0.8%top 47% das CVEs
exploração observada
nãonenhuma fonte reporta
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Produtos afetados
Red Hat · Red Hat Directory Server 11.5 E4S for RHEL 8Red Hat · Red Hat Directory Server 11.7 E4S for RHEL 8Red Hat · Red Hat Directory Server 11.9 for RHEL 8Red Hat · Red Hat Directory Server 12Red Hat · Red Hat Directory Server 12.2 E4S for RHEL 9Red Hat · Red Hat Directory Server 12.4 E4S for RHEL 9Red Hat · Red Hat Directory Server 13Red Hat · Red Hat Directory Server 13.2Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 10.0 Extended Update SupportRed Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7 Extended Lifecycle SupportRed Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRed Hat · Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRed Hat · Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRed Hat · Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.6 Extended Update SupportReferências
https://access.redhat.com/errata/RHSA-2026:36195https://access.redhat.com/errata/RHSA-2026:36196https://access.redhat.com/errata/RHSA-2026:36197https://access.redhat.com/errata/RHSA-2026:36198https://access.redhat.com/errata/RHSA-2026:36200https://access.redhat.com/errata/RHSA-2026:36201https://access.redhat.com/errata/RHSA-2026:36202https://access.redhat.com/errata/RHSA-2026:36204https://access.redhat.com/errata/RHSA-2026:36205https://access.redhat.com/errata/RHSA-2026:36206https://access.redhat.com/errata/RHSA-2026:36208https://access.redhat.com/errata/RHSA-2026:36209