CVE-2026-11788

EUVD-2026-35420
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44.63%
Affected Products (NVD)
VendorProductVersion
redhatdirectory_server
11.0
redhatdirectory_server
12.0
redhatdirectory_server
13.0
redhat389_directory_server
-
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
389-ds-base
bookworm
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
389-ds-base
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
389-ds-base
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-devel
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-libs
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-snmp
RHEL 9
0:2.8.0-9.el9_8
fixed
python3-lib389
RHEL 9
0:2.8.0-9.el9_8
fixed