PT-2026-86816 · Opensuse+2 · 389-Ds+29

CVE-2026-18355

·

Published

2026-09-07

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl io start packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted buffer count below the already-consumed encrypted buffer offset, causing an unsigned subtraction underflow in sasl io read packet(). PR Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.

Fix

RCE

DoS

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64784
CVE-2026-18355
OPENSUSE-SU-2026:11739-1

Affected Products

389-Ds
389-Ds-Base
389-Ds-Base-Devel
389-Ds-Base-Libs
389-Ds-Base-Snmp
Red Hat Directory Server 11
Red Hat Directory Server 11.7 E4S For Rhel 8
Red Hat Directory Server 11.9 For Rhel 8
Red Hat Directory Server 12
Red Hat Directory Server 12.2 E4S For Rhel 9
Red Hat Directory Server 12.4 E4S For Rhel 9
Red Hat Directory Server 13
Red Hat Directory Server 13.2
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 10.0 Extended Update Support
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Enterprise Linux 8.8 Update Services For Sap Solutions
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 9.2 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.4 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.6 Extended Update Support
Python3-Lib389