Integer Overflow Vulnerability in 389 Directory Server by Red Hat
CVE-2026-11774
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 11 June 2026
What is CVE-2026-11774?
An integer overflow vulnerability exists in the SASL I/O layer of the 389 Directory Server. This flaw occurs when a crafted SASL packet length prefix is manipulated, leading to the possible bypassing of the nsslapd-maxsasliosize limit. As a result, this vulnerability can allow an attacker to exploit a heap buffer overflow, potentially enabling them to execute arbitrary code or cause a Denial of Service (DoS). This is particularly concerning in environments like FreeIPA and Red Hat Identity Management, where a remote attacker may leverage this flaw using valid Kerberos credentials to execute their attack over the network.
Affected Version(s)
Red Hat Directory Server 11.5 E4S for RHEL 8 8060020260702180044.0ca98e7e
Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260702180836.f969626e
Red Hat Directory Server 11.9 for RHEL 8 8100020260702145313.37ed7c03