Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16560— 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn

CVSS 5.3 · Medium EPSS 0.40% · P32

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-16560

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1220
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Directory Server 11-cpe:/a:redhat:directory_server:11
Red HatRed Hat Directory Server 12-cpe:/a:redhat:directory_server:12
Red HatRed Hat Directory Server 13-cpe:/a:redhat:directory_server:13
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-16560

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16560

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16560 (2)

Same Patch Batch · Red Hat · 2026-07-22 · 8 CVEs total

CVE-2026-441897.8 HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execut
CVE-2026-441907.8 HIGHAnsible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execut
CVE-2026-441917.8 HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: remote code execution
CVE-2026-441926.6 MEDIUMAnsible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltra
CVE-2026-165446.5 MEDIUMAwx: websocket eventconsumer missing authorization for inventory_update_events, project_up
CVE-2026-164734.3 MEDIUMSbc: sbc: heap out-of-bounds read via crafted sbc audio frame
CVE-2026-441873.3 LOWAnsible-lightspeed: ansible lightspeed extension for visual studio code: information discl

IV. Related Vulnerabilities

V. Comments for CVE-2026-16560

No comments yet


Leave a comment