CVE-2026-11793

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad de desbordamiento de búfer en la pila en 389 Directory Server. La función checkPrefix() en pw.c copia un ID de algoritmo controlado por el atacante en un búfer de pila de 256 bytes sin verificación de límites al analizar valores de atributo cifrados de forma reversible. Un atacante con privilegios de Directory Manager puede provocar la caída del servidor LDAP al almacenar una credencial especialmente diseñada con un ID de algoritmo sobredimensionado. FORTIFY_SOURCE mitiga esto solo a denegación de servicio.

30 Jun 2026, 11:16

Type Values Removed Values Added
References
  • {'url': 'https://redhat.atlassian.net/browse/PSIRTSUPT-7600', 'tags': ['Permissions Required'], 'source': 'secalert@redhat.com'}

15 Jun 2026, 18:34

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-11793 - () https://access.redhat.com/security/cve/CVE-2026-11793 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2484914 - () https://bugzilla.redhat.com/show_bug.cgi?id=2484914 - Issue Tracking, Vendor Advisory
References () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - () https://redhat.atlassian.net/browse/PSIRTSUPT-7600 - Permissions Required
First Time Redhat 389 Directory Server
Redhat
CPE cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-11793

Mitre link : CVE-2026-11793

CVE.ORG link : CVE-2026-11793


JSON object : View

Products Affected

redhat

  • 389_directory_server
CWE
CWE-121

Stack-based Buffer Overflow