VDB

CVE-2026-18355

CVE-2026-18355 PUBLISHED CVSS 7.5 HIGH

Reported by redhat · Published September 7, 2026

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Directory Server 11.7 E4S for RHEL 88080020260903102346.f969626e
Red HatRed Hat Directory Server 11.9 for RHEL 88100020260904171440.37ed7c03
Red HatRed Hat Directory Server 12.2 E4S for RHEL 99020020260903155914.1674d574
Red HatRed Hat Directory Server 12.4 E4S for RHEL 99040020260903102623.1674d574
Red HatRed Hat Enterprise Linux 100:3.2.0-10.el10_2
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:3.0.6-21.el10_0
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.3.11.1-15.el7_9
Red HatRed Hat Enterprise Linux 88100020260904155442.25e700aa
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support8040020260901171549.96015a92
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On8040020260901171549.96015a92
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support8060020260901145727.824efc52
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On8060020260901145727.824efc52
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service8080020260831180218.6dbb3803
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions8080020260831180218.6dbb3803
Red HatRed Hat Enterprise Linux 90:2.8.0-10.el9_8
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:2.2.4-22.el9_2
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:2.4.5-29.el9_4
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:2.6.1-24.el9_6
Red HatRed Hat Directory Server 13.21788851765
Red HatRed Hat Directory Server 12

…and 27 more

Timeline

  • Sep 7, 2026 CVE Published
  • Sep 8, 2026 EPSS Score
  • Sep 8, 2026 Distribution Patch
  • Sep 8, 2026 Security Advisory
  • Sep 8, 2026 Distribution Patch
  • Sep 8, 2026 Security Advisory
  • Sep 8, 2026 CVE Updated
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 Distribution Patch
  • Sep 9, 2026 Distribution Patch
  • Sep 9, 2026 Distribution Patch
  • Sep 9, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›