CVE-2026-11792: 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string)

Published Jun 4, 2026
·
Updated

A heap buffer overflow exists in 389 Directory Server's audit log password masking feature. The createmaskedentrystring() function (auditlog.c:109) uses strcpy to write a fixed 24-byte mask string into a precisely-sized heap buffer from slapientry2str(). When a password value is shorter than 23 characters, the copy overflows past the allocated buffer boundary.

Trigger conditions require non-default configuration: audit logging enabled AND either passwordStorageScheme=CLEAR (explicitly discouraged) or a compromised replication peer sending short cleartext passwords via replicated ADD (replop bypasses password hashing).

Introduced by commit bfeaa8d (Issue 6884, July 2025) and backported to RHEL 9.6 (RHEL-109954) and RHEL 10 (RHEL-107035). Not present in RHEL 7, RHEL 8, or RHEL 9.0-9.5.

Production testing: heap corruption confirmed in audit log output on live server; ASan PoC confirms overflow. Production binaries may absorb overflow in allocator padding without immediate crash.

Advisory: 389-ds-campaign-2026-04/006-Auditlog-Heap-Overflow/advisory.md. Source: PSIRTSUPT-7600 (Ian Murphy, Red Hat Product Security).

Other sources

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the createmaskedentrystring() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default CLEAR password storage or a compromised replication peer), the copy overflows the buffer, corrupting heap memory and audit log output.

MITRE

Affected Software

1 affected component
redhat/389-ds-base=RHEL 9.6, =RHEL 10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch 389-ds-campaign-2026-04/006-Auditlog-Heap-Overflow/advisory.md
  2. Configuration

    If possible, disable audit logging on production instances to avoid triggering the heap buffer overflow in password masking (create_masked_entry_string in auditlog.c) until the advisory patch is applied. Trigger conditions require audit logging enabled.

    389 Directory Server (audit logging) audit logging enabled = disabled
  3. Compensating control

    Mitigate the trigger by preventing replicated ADD operations from carrying short cleartext passwords. Ensure replication peers cannot bypass password hashing (repl_op bypasses password hashing when sending short cleartext passwords via replicated ADD) and avoid non-default cleartext password handling (passwordStorageScheme=CLEAR is explicitly discouraged).

Event History

Jun 4, 2026
Data Sourced
via Red Hat·08:43 PM
DescriptionSeverityAffected Software
Jun 9, 2026
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11792?

The severity of CVE-2026-11792 is classified as low, with a score of 3.3.

2

How do I fix CVE-2026-11792?

To fix CVE-2026-11792, you should update your 389-ds-base software to the latest version provided by Red Hat.

3

What type of vulnerability is CVE-2026-11792?

CVE-2026-11792 is classified as a heap buffer overflow vulnerability.

4

What is affected by CVE-2026-11792?

CVE-2026-11792 affects the 389 Directory Server's audit log password masking feature.

5

What could happen if CVE-2026-11792 is exploited?

If exploited, CVE-2026-11792 may lead to potential unauthorized access due to heap buffer overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203