Dereference Control Flaw in 389 Directory Server by Red Hat
CVE-2026-11788

5.9MEDIUM

What is CVE-2026-11788?

A vulnerability exists in the 389 Directory Server related to the dereference control plugin, which does not adequately verify allocation failures prior to utilizing a BER structure. This oversight can enable an unauthenticated remote attacker to crash the LDAP server, particularly under conditions of memory strain, potentially leading to significant service interruptions.

Affected Version(s)

Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260806114250.f969626e

Red Hat Directory Server 11.9 for RHEL 8 8100020260803140625.37ed7c03

Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260730155601.1674d574

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.