Junglewise Threat Intelligence

CVE-2026-15041: 389 Directory Server timing side-channel in PBKDF2-SHA256 comparison

CVE-2026-15041 · Severity: low · CVSS 3.7 · Published 2026-07-08

Technologies: 389 Project 389 Directory Server, Red Hat Enterprise Linux. Vendors: Red Hat.

Executive brief

389 Directory Server is an enterprise-grade LDAP server used to manage user identities and authentication across a network. A security flaw was identified where the system compares password hashes using a method that takes different amounts of time depending on how much of the password is correct. While extremely difficult to perform in practice, a sophisticated attacker could theoretically use these timing differences to gradually guess parts of a user's encrypted password information.

Technical details

A timing side-channel vulnerability (CWE-208) exists in the PBKDF2-SHA256 password verification function `pbkdf2_sha256_pw_cmp()` within `ldap/servers/plugins/pwdstorage/pbkdf2_pwd.c`. The component uses standard `memcmp()` instead of the constant-time `slapi_ct_memcmp()` function, which is used by other storage schemes in the same plugin. A remote, unauthenticated attacker can attempt to measure the time taken for LDAP bind operations to leak information about the stored password hash. However, exploitation is considered highly impractical because the high computational overhead of PBKDF2 iterations (typically 8192+) significantly masks the nanosecond-scale timing differences of the memory comparison.

Affected products

  • 389 Project 389 Directory Server All versions using PBKDF2-SHA256 password storage
  • Red Hat Red Hat Directory Server 11, 12, 13
  • Red Hat Red Hat Enterprise Linux 6, 7, 8, 9, 10

Timeline

  • 2026-07-08: disclosed: Vulnerability reported and recorded in Red Hat Bugzilla
  • 2026-07-08: advisory: CVE-2026-15041 published

References