CVE-2026-11610Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-07); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-07: 3Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 307-0707-08
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-073
Disclosure3
2026-07-081
Disclosure1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Red Hat 389 Directory Server (CVE-2026-11610) https://vuldb.com/vuln/376758

    Post summary

    A severe vulnerability was disclosed in Red Hat 389 Directory Server (CVE-2026-11610), with no additional technical details or evidence of exploitation provided.

    00000123
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-11610 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), a… https://www.cve.org/CVERecord?id=CVE-2026-11610 ----- Traducción: CVE-2026-11610 Se … http://infoflow.cloud`

    Post summary

    The notice announces a heap buffer overflow in 389 Directory Server’s SASL I/O layer, citing the CVE ID and linking to the CVE report, but offers no PoC, exploit code, evidence of active exploitation, patch, or debunking.

    0000034
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-11610 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), a… https://www.cve.org/CVERecord?id=CVE-2026-11610

    Post summary

    The article announces CVE‑2026‑11610 as a heap buffer overflow in 389 Directory Server's SASL I/O layer, providing technical details but no PoC, exploit code, or patch information.

    00000715
    57.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - 389 Directory Server Heap Buffer Overflow in SASL I/O (CVE-2026-11610) A heap buffer overflow was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection, an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that overflows a 512-byte heap receive buffer in sasl_io_recv(). This allows up to ~2 MB of attacker-controlled data to overflow the buffer, leading to memory corruption or denial of service (server crash). In FreeIPA/Red Hat Identity Management, any domain user with a valid Kerberos ticket can trigger it. 👉Affected: 389-ds-base 11.0 – 11.12.4_Update1, 12.0 – 12.12, 2025.1 – 2026.2 Action: Update to the latest patched version of 389 Directory Server.

    Post summary

    The text discloses CVE-2026-11610, a heap buffer overflow in 389 Directory Server's SASL I/O layer, provides technical details, and recommends applying the latest patch.

    00000159
    243 followersView on X

Explore more