CVE-2026-11792

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default CLEAR password storage or a compromised replication peer), the copy overflows the buffer, corrupting heap memory and audit log output.
Configurations

No configuration.

History

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-06-09 14:42


NVD link : CVE-2026-11792

Mitre link : CVE-2026-11792

CVE.ORG link : CVE-2026-11792


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow