PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11789 Red Hat CVE debrief

CVE-2026-11789 is a MEDIUM-severity vulnerability affecting 389 Directory Server. The SMD5 password storage plugin is vulnerable to an unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes. This causes a buffer over-read that crashes the LDAP server during authentication.

Vendor
Red Hat
Product
Red Hat Directory Server 11
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-30
Advisory published
2026-06-09
Advisory updated
2026-06-30

Who should care

Users of 389 Directory Server, particularly those using the SMD5 password storage plugin, should be aware of this vulnerability. This includes administrators of Red Hat Directory Server, Red Hat Enterprise Linux, and other affected systems.

Technical summary

The SMD5 password storage plugin in 389 Directory Server performs an unsigned integer underflow when computing the salt length from a crafted password hash that is shorter than 16 bytes. This underflow leads to a buffer over-read, which causes the LDAP server to crash during authentication.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply patches or updates provided by the vendor to address the vulnerability.
  • Restrict access to the LDAP server to trusted users and networks.
  • Monitor server logs for signs of exploitation attempts.

Evidence notes

The vulnerability was reported by Red Hat and is tracked as CVE-2026-11789. The CVSS score is 4.9, indicating a MEDIUM severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11789 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11789

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11789 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11789

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.