CVE-2026-11790: 389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service

Published Jun 5, 2026
·
Updated

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

Other sources

The PBKDF2-SHA256 password storage plugin in 389 Directory Server extracts the iteration count from stored password hashes without an upper bound check. An attacker with Directory Manager privileges can plant a crafted {PBKDF2SHA256} hash with extreme iteration counts (e.g. 0x7FFFFFFF). Any subsequent LDAP BIND as the poisoned account triggers unbounded CPU consumption, hanging a worker thread for hours and enabling persistent denial of service.

Both the C plugin (pbkdf2pwd.c) and Rust plugin (pwdchan/lib.rs) are affected. Distinct from CVE-2024-5953 which added hash length check but not iteration cap.

Introduced in 389-ds-base 1.3.6 (commit 542287ce7, Ticket 397). PoC confirmed on Fedora 42 production binary.

Red Hat

Affected Software

9 affected components
389 Project 389-ds-base>=1.3.6
redhat Directory Server=11.0
redhat Directory Server=12.0
redhat Directory Server=13.0
redhat 389 Directory Server=1.3.6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Event History

Jun 5, 2026
Data Sourced
via Red Hat·12:24 PM
DescriptionSeverityAffected Software
Jun 9, 2026
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11790?

The severity of CVE-2026-11790 is rated as medium with a score of 4.9.

2

What kind of attack does CVE-2026-11790 enable?

CVE-2026-11790 enables a denial of service attack due to unbounded iteration count in the PBKDF2 password storage plugin.

3

How do I fix CVE-2026-11790?

To mitigate CVE-2026-11790, ensure you are using a patched version of the 389-ds-base software that addresses this vulnerability.

4

Who is affected by CVE-2026-11790?

CVE-2026-11790 affects users of the 389 Directory Server with the PBKDF2-SHA256 password storage plugin.

5

What can happen if CVE-2026-11790 is exploited?

If exploited, CVE-2026-11790 can lead to excessive CPU consumption during the authentication process, impacting server availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203