Junglewise Threat Intelligence

CVE-2026-18355: Red Hat 389 Directory Server heap buffer overflow in SASL I/O

CVE-2026-18355 · Severity: high · CVSS 7.5 · Published 2026-09-07

Technologies: Red Hat 389-Ds-Base. Vendors: Red Hat.

Executive brief

389 Directory Server is an open-source LDAP directory service used to store and manage user and group information in enterprise environments. A heap buffer overflow in its SASL authentication layer allows authenticated attackers to crash the service or potentially execute arbitrary code after successfully binding with integrity protection enabled. This could disrupt critical authentication and directory services.

Technical details

A heap buffer overflow exists in the sasl_io_start_packet() and sasl_io_read_packet() functions of 389 Directory Server's SASL I/O layer. The vulnerability is triggered when the wrapped-record length from the wire is validated only against an upper bound; a small wire length (0, 1, or 2 bytes) causes an integer underflow in the encrypted_buffer_count calculation, leading to PR_Recv attempting to read approximately 4 GiB into a 1024-byte heap buffer. The attack requires prior successful SASL authentication with integrity protection (SSF > 0), meaning the attacker must be a valid directory user. An attacker can achieve denial of service by crashing the server or potentially remote code execution via heap corruption with attacker-controlled data. Patches are available from Red Hat.

Affected products

  • Red Hat 389 Directory Server

Timeline

  • 2026-09-07: disclosed

References