CVE-2026-11789

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:13.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en 389 Directory Server. El plugin de almacenamiento de contraseñas SMD5 realiza un subdesbordamiento de entero sin signo al calcular la longitud del salt a partir de un hash de contraseña manipulado de menos de 16 bytes, lo que provoca una lectura excesiva del búfer que bloquea el servidor LDAP durante la autenticación.

30 Jun 2026, 14:16

Type Values Removed Values Added
References
  • {'url': 'https://redhat.atlassian.net/browse/PSIRTSUPT-7600', 'tags': ['Permissions Required'], 'source': 'secalert@redhat.com'}

12 Jun 2026, 18:30

Type Values Removed Values Added
First Time Redhat directory Server
Redhat enterprise Linux
Redhat 389 Directory Server
Redhat
References () https://access.redhat.com/security/cve/CVE-2026-11789 - () https://access.redhat.com/security/cve/CVE-2026-11789 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2485422 - () https://bugzilla.redhat.com/show_bug.cgi?id=2485422 - Issue Tracking, Vendor Advisory
References () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - Permissions Required
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:13.0:*:*:*:*:*:*:*

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-11789

Mitre link : CVE-2026-11789

CVE.ORG link : CVE-2026-11789


JSON object : View

Products Affected

redhat

  • directory_server
  • 389_directory_server
  • enterprise_linux
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)