Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Directory Server 11 — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Red Hat Directory Server 11, with AI-generated Chinese analysis, references, and POCs.

This page presents vulnerability aggregation data for Red Hat Directory Server 11, categorized by common weakness type and specific product tags. It collects a comprehensive range of security flaws affecting this directory service platform, spanning from initial release through to current maintenance updates. Readers can utilize this resource to track vendor security advisories, gain a deeper understanding of prevalent weakness classifications, and examine the historical vulnerability profile of the software. The data serves as a centralized reference for security professionals evaluating risk exposure, patch management priorities, and compliance requirements related to directory authentication and authorization services. By consolidating disparate reports into a single view, the page facilitates efficient analysis of threat landscapes specific to Red Hat’s enterprise directory solutions. Information is structured to support rapid identification of critical issues, review of remediation timelines, and comparison against industry benchmarks. This approach enables administrators to make informed decisions regarding system hardening and update strategies without navigating multiple external sources. The content reflects publicly disclosed vulnerabilities and associated vendor guidance, ensuring accuracy and relevance for operational security planning. All entries are sourced from official Red Hat security channels and recognized vulnerability databases to maintain integrity and traceability. Users are encouraged to cross-reference this summary with detailed technical advisories for implementation-specific guidance and patch verification procedures.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-11791 389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht() CWE-416 5.0 Medium2026-06-18
CVE-2026-12528 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt() CWE-787 5.4 Medium2026-06-17
CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow CWE-190 7.6 High2026-06-11
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation CWE-122 6.5 Medium2026-06-10
CVE-2026-11792 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string) CWE-122 3.3 Low2026-06-09
CVE-2026-11793 389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id parsing CWE-121 4.9 Medium2026-06-09
CVE-2026-11790 389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service CWE-400 4.9 Medium2026-06-09
CVE-2026-11789 389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash CWE-191 4.9 Medium2026-06-09
CVE-2026-11788 389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser CWE-476 5.9 Medium2026-06-09
CVE-2026-11787 389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing CWE-126 5.0 Medium2026-06-09
CVE-2026-11785 389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler CWE-843 4.3 Medium2026-06-09
CVE-2026-11786 389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type() CWE-125 1.9 Low2026-06-09
CVE-2026-11611 389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions CWE-400 6.5 Medium2026-06-08

All 13 known CVE vulnerabilities affecting Red Hat Directory Server 11 with full Chinese analysis, references, and POCs where available.