VDB

CVE-2026-11884

CVE-2026-11884 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published June 10, 2026

A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager privileges, or a compromised replication supplier, can trigger a server crash by creating objectclasses with long SUP values. This is an incomplete fix variant of CVE-2025-14905.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Directory Server 11
Red HatRed Hat Directory Server 12
Red HatRed Hat Directory Server 13
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Directory Server 11
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Directory Server 13
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Directory Server 12

Timeline

  • Jun 10, 2026 CVE Published
  • Jun 11, 2026 Coalition ESS Score
  • Jun 12, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 8, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›