CVE-2026-11610
Last modified
CVE-2026-11610 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 389ds | 389-ds-base | >= 1.3.2, <= 3.3.0 |
| Red Hat | Red Hat Directory Server 11.5 E4S for RHEL 8 | All versions |
| Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | All versions |
| Red Hat | Red Hat Directory Server 11.9 for RHEL 8 | All versions |
| Red Hat | Red Hat Directory Server 12.2 E4S for RHEL 9 | All versions |
| Red Hat | Red Hat Directory Server 12.4 E4S for RHEL 9 | All versions |
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | All versions |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | All versions |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | All versions |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | All versions |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | All versions |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | All versions |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | All versions |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | All versions |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | All versions |
| Red Hat | Red Hat Directory Server 13.2 | All versions |
| Red Hat | Red Hat Directory Server 12 | All versions |
| Red Hat | Red Hat Enterprise Linux 6 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-11610?
How severe is CVE-2026-11610?
How do I fix CVE-2026-11610?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11600The Envo's Templates & Widgets for Elementor and WooCommerce…4.3
- CVE-2026-11603The Product Filter Widget for Elementor plugin for WordPress…6.1
- CVE-2026-11604An incorrect buffer size calculation in the epoch key genera…6.5
- CVE-2026-11605The issue is a resource exhaustion vulnerability associated …7.5
- CVE-2026-11607Backend users with access to the Form Framework were able to…7.6
- CVE-2026-1161A vulnerability was detected in pbrong hrms 1.0.1. The affec…3.5
- CVE-2026-11611A flaw was found in 389 Directory Server. The Content Synchr…6.5
- CVE-2026-11612Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-11614The Xpro Addons — 140+ Widgets for Elementor plugin for Word…6.4
- CVE-2026-11616The Events Calendar for GeoDirectory plugin for WordPress is…8.8
- CVE-2026-11618A vulnerability was determined in DTStack Taier up to 1.4.0.…7.3
- CVE-2026-11619A vulnerability was identified in Dolibarr ERP CRM up to 23.…6.3
Are you affected by CVE-2026-11610?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
