Heap Buffer Overflow in 389 Directory Server by Red Hat
CVE-2026-11884
6.5MEDIUM
What is CVE-2026-11884?
A heap buffer overflow vulnerability has been identified in the 389 Directory Server, primarily affecting objectclass definitions. The issue arises from the omission of the oc_superior (SUP) field length in buffer size calculations during the serialization processes in read_schema_dse() and schema_oc_to_string(). Malicious actors with Directory Manager privileges or compromised replication suppliers can exploit this flaw to create objectclasses with excessively long SUP values, potentially leading to server crashes. This vulnerability is known to be an incomplete fix variant of a previous issue, highlighting the need for immediate attention and remediation.