389-DS SASL I/O Heap Overflow via Small-Length Underflow
CVE-2026-18355 Published on September 7, 2026
389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
Vulnerability Analysis
CVE-2026-18355 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public. 61 days later.
Weakness Type
What is an Integer underflow Vulnerability?
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result. This can happen in signed and unsigned cases.
CVE-2026-18355 has been classified to as an Integer underflow vulnerability or weakness.
Products Associated with CVE-2026-18355
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Directory Server 11.7 E4S for RHEL 8:- Version 8080020260903102346.f969626e and below * is unaffected.
- Version 8100020260904171440.37ed7c03 and below * is unaffected.
- Version 9020020260903155914.1674d574 and below * is unaffected.
- Version 9040020260903102623.1674d574 and below * is unaffected.
- Version 0:3.2.0-10.el10_2 and below * is unaffected.
- Version 0:3.0.6-21.el10_0 and below * is unaffected.
- Version 0:1.3.11.1-15.el7_9 and below * is unaffected.
- Version 8100020260904155442.25e700aa and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 0:2.8.0-10.el9_8 and below * is unaffected.
- Version 0:2.2.4-22.el9_2 and below * is unaffected.
- Version 0:2.4.5-29.el9_4 and below * is unaffected.
- Version 0:2.6.1-24.el9_6 and below * is unaffected.
- Version 1788851765 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.