Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Restrict Directory Manager access. Monitor cn=config attributes (nsDS5ReplicaCredentials, nsDS5ReplicaBootstrapCredentials) for abnormally long values. Restrict LDAP administrative access to management networks or localhost (LDAPI).
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat 389 Directory Server
|
|
| CPEs | cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Redhat 389 Directory Server
|
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat redhat Directory Server
|
|
| Vendors & Products |
Redhat redhat Directory Server
|
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. | |
| Title | 389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id parsing | |
| First Time appeared |
Redhat
Redhat directory Server Redhat enterprise Linux |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:/a:redhat:directory_server:11 cpe:/a:redhat:directory_server:12 cpe:/a:redhat:directory_server:13 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat directory Server Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-09T13:29:33.535Z
Reserved: 2026-06-09T13:04:58.380Z
Link: CVE-2026-11793
Updated: 2026-06-09T13:29:27.407Z
Status : Analyzed
Published: 2026-06-09T14:16:37.503
Modified: 2026-06-15T18:34:31.470
Link: CVE-2026-11793
No data.
OpenCVE Enrichment
Updated: 2026-06-09T20:20:38Z