CVE-2026-15722

EUVD-2026-51509
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 55.51%
Affected Products (NVD)
VendorProductVersion
redhatdirectory_server
11.0
redhatdirectory_server
12.0
redhat389_directory_server
-
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
389-ds-base
bookworm
vulnerable
sid
3.3.1-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
389-ds-base
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
389-ds-base
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-devel
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-libs
RHEL 9
0:2.8.0-9.el9_8
fixed
389-ds-base-snmp
RHEL 9
0:2.8.0-9.el9_8
fixed
python3-lib389
RHEL 9
0:2.8.0-9.el9_8
fixed