Junglewise Threat Intelligence

CVE-2026-11787: Red Hat 389 Directory Server heap buffer over-read in ldap_utf8prev

CVE-2026-11787 · Severity: medium · CVSS 5 · Published 2026-06-09

Vendors: Red Hat.

Executive brief

A security flaw was identified in 389 Directory Server, an enterprise-grade LDAP server used for identity management. A technical error in how the server processes specific text strings could allow an attacker to read small amounts of restricted memory. While this is unlikely to cause a system crash, it could potentially interfere with internal security rules or expose sensitive configuration data.

Technical details

A heap buffer over-read exists in the ldap_utf8prev() function within 389-ds-base. The function lacks proper bounds checking and can unconditionally read up to 6 bytes before the start of a heap allocation. While the standard LDAP wire protocol (BER filters) is not directly affected, the vulnerability can be triggered via internal callers that process attacker-influenced data, such as plugin configurations, Access Control Instruction (ACI) definitions, or replication data. An authenticated attacker with the ability to modify these configurations could potentially influence internal filter processing or leak small amounts of memory. The issue stems from a legacy API design flaw in the Mozilla LDAP C SDK.

Affected products

  • Red Hat 389 Directory Server (389-ds-base) All versions prior to fix

Timeline

  • 2026-06-05: disclosed: Reported via Red Hat Bugzilla
  • 2026-06-09: advisory: NVD and Red Hat published advisory details

References