Aller au contenu

Fiche vulnérabilité

CVE-2026-11791 : faille moyenne redhat directory server (CVSS 5.0)

Description

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

En bref

Sévérité
Moyenne (CVSS 5.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Exploitation active
Non signalée par la CISA
Publication
18 juin 2026
Dernière mise à jour
30 juin 2026

Produits concernés

  • redhat directory server
  • redhat 389 directory server
  • redhat enterprise linux

Références

Rechercher une autre vulnérabilité dans la base CVE