Back to overview

CVE-2026-11786

LOW
1.9
CVSS 3.1
Description
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.

Metadata

CVE ID
CVE-2026-11786
State
PUBLISHED
Assigner
redhat
Reserved
2026-06-09 12:54 UTC
Published
2026-06-09 12:57 UTC
Last updated
2026-06-09 13:38 UTC
Primary CWE
CWE-125
Out-of-bounds Read
Vendor / Product
Red Hat / Red Hat Directory Server 11
Sources
cve.org  ·  NVD

Severity & Metrics

1.9 LOW CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (8)
VendorProductPlatformVersions
Red Hat Red Hat Directory Server 11
Red Hat Red Hat Directory Server 12
Red Hat Red Hat Directory Server 13
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 9
Weakness (CWE)
CWESourceDescription
CWE-125 cna Out-of-bounds Read
CVSS scores (1)
ScoreSeverityVersionSourceVector
1.9 LOW 3.1 cna CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Back to overview