VYPR
Medium severity5.9NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-11788

CVE-2026-11788

Description

389 Directory Server's dereference control plugin crashes when memory allocation fails, allowing unauthenticated remote attackers to cause a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

389 Directory Server's dereference control plugin crashes when memory allocation fails, allowing unauthenticated remote attackers to cause a denial of service.

Vulnerability

A flaw exists in the dereference control plugin of 389 Directory Server where it fails to check the return value of ber_init() before use in deref_parse_ctrl_value() within deref.c. This issue is present in versions since the introduction of the dereference plugin in 389-ds-base 1.2.6. The dereference control plugin is enabled by default [2].

Exploitation

An unauthenticated remote attacker can trigger this vulnerability by sending a search request with the dereference control to the LDAP server. This attack is most likely to succeed when the system is under memory pressure, causing memory allocation to fail [2].

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to crash the ns-slapd process, resulting in a denial of service for the LDAP server. The crash has been confirmed via GDB fault injection on Fedora 42 (SIGABRT) and CentOS 7 (SIGSEGV) [2].

Mitigation

This vulnerability has been fixed. The vulnerable code was present since 389-ds-base 1.2.6. No specific fixed version or release date is available in the provided references, but the issue is tracked in Bugzilla [2]. Users should consult Red Hat advisories for specific patch information [1].

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.