CVE-2026-15041
EUVD-2026-4221308.07.2026, 11:16
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | directory_server | 11.0 |
| redhat | directory_server | 12.0 |
| redhat | directory_server | 13.0 |
| redhat | 389_directory_server | - |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases