High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND
This high-severity Red Hat Linux advisory covers CVE-2026-11610 affecting Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 1, Red Hat Enterprise Linux 7.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8).
Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03.
Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
- 1.3.2
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- redhat-ds:11-8060020260702180044.0ca98e7e
- 389-ds:1.4-8060020260626130540.824efc52
- redhat-ds:12-9040020260703055735.1674d574
- redhat-ds:11-8100020260702145313.37ed7c03
- 389-ds:1.4-8040020260629123121.96015a92
- 389-ds-base-0:2.6.1-22.el9_6
- 389-ds-base-0:2.8.0-8.el9_8
- dirsrv/dirsrv-container-rhel10:1783452100
- 389-ds-base-0:3.0.6-19.el10_0
- 389-ds-base-0:2.2.4-19.el9_2
- 389-ds-base-0:1.3.11.1-13.el7_9
- 389-ds:1.4-8080020260630025241.6dbb3803
- redhat-ds:12-9020020260703060155.1674d574
- 389-ds:1.4-8100020260626120929.25e700aa
- 389-ds-base-0:2.4.5-26.el9_4
- redhat-ds:11-8080020260702180836.f969626e
- 389-ds-base-0:3.2.0-8.el10_2
- RHSA-2026:36209
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation checklist
- There is no complete workaround for this flaw. Mitigations that reduce exposure: 1. Restrict network access to LDAP ports (389/636) to trusted networks only. Note: In FreeIPA/IdM deployments, enrolled clients require LDAP access and this may not be practical. 2. If DIGEST-MD5 is not required, disable it via nsslapd-allowed-sasl-mechanisms in cn=config. GSSAPI/Kerberos cannot be disabled in FreeIPA/IdM without breaking domain authentication. 3. Monitor for oversized LDAP UNBIND packets (standard UNBIND is 7 bytes; alert on UNBIND packets exceeding ~100 bytes). 4. Lowering nsslapd-maxbersize reduces maximum overflow size but does not eliminate the vulnerability.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.