CVE-2026-18355

7.5

Red Hat · Directory Server

A heap buffer overflow in the SASL I/O layer of 389 Directory Server allows an authenticated remote attacker to trigger a denial of service or potentially achieve remote code execution.

Executive summary

A heap buffer overflow vulnerability in Red Hat Directory Server, rated as High severity, poses a significant risk of remote code execution for organizations running affected RHEL environments.

Vulnerability

This flaw is a heap buffer overflow resulting from an integer underflow in the SASL I/O layer, specifically within the sasl_io_read_packet function. A remote attacker with low-level authentication can trigger this overflow by sending a specially crafted packet after a successful SASL bind.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting its high potential for impact despite the requirement for initial authentication. Successful exploitation may lead to full system compromise or service disruption, threatening the integrity and availability of critical identity management infrastructure. Such a breach could result in unauthorized access to sensitive directory data and significant operational downtime.

Remediation

Immediate Action: Apply the specific security updates provided by Red Hat in the associated errata (RHSA-2026:64771 through RHSA-2026:64784) immediately to patch the vulnerable SASL I/O layer.

Proactive Monitoring: Review directory server access logs for anomalous SASL bind activity or unexpected service crashes that may indicate exploitation attempts.

Compensating Controls: Ensure strict access control lists are in place for the directory service to minimize the population of users capable of performing a SASL bind, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution in a critical identity component, this vulnerability must be treated with high urgency. Administrators should verify their current version of 389-ds-base against the fixed versions provided by Red Hat and prioritize deployment of the relevant security errata. Failure to patch may leave directory infrastructure exposed to sophisticated actors capable of escalating their privileges through the SASL I/O layer.

More Red Hat CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and T, per the CVE Program record.