Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-15722

CVE-2026-15722: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing

    CVE-2026-15722Source published Source updated

    A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service. The overflow data is limited to ASCII digit characters and a null byte. Stack protectors and ASLR prevent the overflow from being leveraged for code execution — the stack canary detects the corruption and aborts the…

    Affected products in this advisory
    • Red Hat Directory Server 11.7 E4S for RHEL 8
    • Red Hat Directory Server 11.9 for RHEL 8
    • Red Hat Directory Server 12.2 E4S for RHEL 9
    • Red Hat Directory Server 12.4 E4S for RHEL 9

    13 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • redhat-ds:11-8080020260806114250.f969626e
    • redhat-ds:11-8100020260803140625.37ed7c03
    • redhat-ds:12-9020020260730155601.1674d574
    • redhat-ds:12-9040020260810131422.1674d574

    26 more entries in the full advisory.

    Mitigation guidance
    • Disable anonymous access by setting nsslapd-allow-anonymous-access to 'off' or 'rootdse' in cn=config. Alternatively, restrict network access to the LDAP port to trusted replication partners only using firewall rules.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery