Heap Buffer Overflow in 389 Directory Server by Red Hat
CVE-2026-11786

1.9LOW

What is CVE-2026-11786?

A vulnerability exists in 389 Directory Server's LDIF parser, where it improperly processes attribute types containing trailing semicolons during database imports. This flaw allows the parser to read beyond the allocated memory buffer, potentially resulting in an out-of-bounds read. It poses significant risks when memory instrumentation tools are employed, as they can detect the overflow, thus exposing sensitive information or causing unintended behavior in the application.

References

CVSS V3.1

Score:
1.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.