PatchSiren cyber security CVE debrief
CVE-2026-11789 Red Hat CVE debrief
CVE-2026-11789 is a MEDIUM-severity vulnerability affecting 389 Directory Server. The SMD5 password storage plugin is vulnerable to an unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes. This causes a buffer over-read that crashes the LDAP server during authentication.
- Vendor
- Red Hat
- Product
- Red Hat Directory Server 11
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-09
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-09
- Advisory updated
- 2026-06-30
Who should care
Users of 389 Directory Server, particularly those using the SMD5 password storage plugin, should be aware of this vulnerability. This includes administrators of Red Hat Directory Server, Red Hat Enterprise Linux, and other affected systems.
Technical summary
The SMD5 password storage plugin in 389 Directory Server performs an unsigned integer underflow when computing the salt length from a crafted password hash that is shorter than 16 bytes. This underflow leads to a buffer over-read, which causes the LDAP server to crash during authentication.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the vulnerability.
- Restrict access to the LDAP server to trusted users and networks.
- Monitor server logs for signs of exploitation attempts.
Evidence notes
The vulnerability was reported by Red Hat and is tracked as CVE-2026-11789. The CVSS score is 4.9, indicating a MEDIUM severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-11789 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-11789
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-11789 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11789
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-11789
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://redhat.atlassian.net/browse/PSIRTSUPT-7600
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.