CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:13.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en 389 Directory Server. La función ldap_utf8prev() lee bytes antes del inicio de un búfer sin comprobación de límites, causando una sobrelectura del búfer de pila en el análisis de filtros de cadena que puede influir en el comportamiento interno de procesamiento de filtros.

30 Jun 2026, 09:16

Type Values Removed Values Added
References
  • {'url': 'https://redhat.atlassian.net/browse/PSIRTSUPT-7600', 'tags': ['Permissions Required'], 'source': 'secalert@redhat.com'}

12 Jun 2026, 18:38

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-11787 - () https://access.redhat.com/security/cve/CVE-2026-11787 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2485425 - () https://bugzilla.redhat.com/show_bug.cgi?id=2485425 - Issue Tracking, Vendor Advisory
References () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - Permissions Required
First Time Redhat directory Server
Redhat enterprise Linux
Redhat 389 Directory Server
Redhat
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:13.0:*:*:*:*:*:*:*

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-11787

Mitre link : CVE-2026-11787

CVE.ORG link : CVE-2026-11787


JSON object : View

Products Affected

redhat

  • directory_server
  • 389_directory_server
  • enterprise_linux
CWE
CWE-126

Buffer Over-read