{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3a389_directory_server_project389-ds-base/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389_directory_server_project:389-ds-base:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-11774"},{"cvss":7.5,"id":"CVE-2026-18355"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389-ds-base"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eA heap buffer overflow vulnerability exists in the SASL I/O layer of 389 Directory Server (389-ds-base), specifically within the sasl_io_read_packet() function. The flaw occurs because the wrapped-record length read from the wire is insufficiently validated. When an attacker provides a small wire length (0, 1, or 2) during a SASL bind with integrity protection (SSF \u0026gt; 0), the application performs an unsigned subtraction underflow when calculating the buffer count. This logic error instructs the system to read approximately 4 GiB of data into a 1024-byte heap-allocated buffer.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows a remote authenticated attacker to trigger memory corruption, leading to a denial of service (DoS) or potentially remote code execution (RCE). This issue is distinct from the previously reported CVE-2026-11774, as the earlier mitigation only addressed upper-bound overflows and failed to account for these specific underflow scenarios.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this flaw can result in a crash of the 389 Directory Server process, causing service disruption. Furthermore, the ability to trigger a heap overflow with attacker-controlled content provides a pathway for remote code execution, which could lead to full system compromise of servers running 389-ds-base.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview security patches provided by the 389 Directory Server project and apply updates to 389-ds-base immediately to address CVE-2026-18355.\u003c/li\u003e\n\u003cli\u003eMonitor service logs for unexpected 389 Directory Server process crashes or restarts, which may indicate attempted exploitation.\u003c/li\u003e\n\u003cli\u003eRestrict access to Directory Server management interfaces to trusted administrative segments to reduce the risk of exploitation by unauthorized or partially authenticated entities.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T15:33:44Z","date_published":"2026-09-07T15:33:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-389-ds-heap-overflow/","summary":"A heap buffer overflow vulnerability in the SASL I/O layer of 389-ds-base allows a remote authenticated attacker to trigger an unsigned subtraction underflow and cause memory corruption.","title":"Heap Buffer Overflow in 389 Directory Server SASL I/O Layer","url":"https://feed.craftedsignal.io/briefs/2026-09-389-ds-heap-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:389_directory_server_project:389-Ds-Base:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}