CVE-2026-11774: Integer Overflow or Wraparound in Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
AI Analysis
Technical Summary
An integer overflow in sasl_io_start_packet() of 389 Directory Server's SASL I/O layer allows an attacker to bypass the nsslapd-maxsasliosize limit by causing an unsigned wraparound when adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC. This leads to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause denial of service or achieve remote code execution. In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can exploit this vulnerability over the network. This issue is distinct from CVE-2025-14905 and affects 389-ds-base versions >=9.0.0 <9.8 and >=10.0.0 <10.2. Red Hat has issued security advisories RHSA-2026:36195 and RHSA-2026:36196 providing updated packages that fix this vulnerability.
Potential Impact
Successful exploitation can lead to denial of service or remote code execution on affected systems running vulnerable versions of 389 Directory Server. The vulnerability allows an attacker with valid SASL bind credentials and integrity protection to bypass packet size limits and overflow heap buffers with attacker-controlled data. This elevates the risk of system compromise or service disruption in environments using Red Hat Directory Server, FreeIPA, or Red Hat Identity Management.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in 389-ds-base packages for Red Hat Enterprise Linux 9 and 10. Users should apply these updates as described in Red Hat advisories RHSA-2026:36195 and RHSA-2026:36196. The advisories provide detailed instructions and updated package versions. Applying these patches mitigates the vulnerability. There are no vendor statements indicating that no action is required or that the issue is already mitigated without patching.
CVE-2026-11774: Integer Overflow or Wraparound in Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8
Description
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
CVSS v3.1
Score 7.6high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An integer overflow in sasl_io_start_packet() of 389 Directory Server's SASL I/O layer allows an attacker to bypass the nsslapd-maxsasliosize limit by causing an unsigned wraparound when adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC. This leads to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause denial of service or achieve remote code execution. In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can exploit this vulnerability over the network. This issue is distinct from CVE-2025-14905 and affects 389-ds-base versions >=9.0.0 <9.8 and >=10.0.0 <10.2. Red Hat has issued security advisories RHSA-2026:36195 and RHSA-2026:36196 providing updated packages that fix this vulnerability.
Potential Impact
Successful exploitation can lead to denial of service or remote code execution on affected systems running vulnerable versions of 389 Directory Server. The vulnerability allows an attacker with valid SASL bind credentials and integrity protection to bypass packet size limits and overflow heap buffers with attacker-controlled data. This elevates the risk of system compromise or service disruption in environments using Red Hat Directory Server, FreeIPA, or Red Hat Identity Management.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in 389-ds-base packages for Red Hat Enterprise Linux 9 and 10. Users should apply these updates as described in Red Hat advisories RHSA-2026:36195 and RHSA-2026:36196. The advisories provide detailed instructions and updated package versions. Applying these patches mitigates the vulnerability. There are no vendor statements indicating that no action is required or that the issue is already mitigated without patching.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-09T11:57:25.581Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-11774","vendor":"Red Hat"}]
Threat ID: 6a2b05c8815e7002b81e9b56
Added to database: 06/11/2026, 19:00:24 UTC
Last enriched: 07/18/2026, 14:37:15 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 122
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.