CVE-2026-11791

medium
Published 2026-06-18 · Modified 2026-06-18
CVSS v3
5.0
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
CVSS v4 NEW
—
not yet in upstream
VIR risk
5.0

Description

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).

Predictions

Exploit likelihood
60%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-11791 NameCVE-2026-11791 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus 389-ds-base (PTS)bullseye1.4.4.11-2vulnerable bullseye…

CVE-2026-11791

NameCVE-2026-11791
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
389-ds-base (PTS)bullseye1.4.4.11-2vulnerable
bullseye (security)1.4.4.11-2+deb11u1vulnerable
bookworm2.3.1+dfsg1-1+deb12u1vulnerable
trixie3.1.2+dfsg1-1+deb13u1vulnerable
sid3.1.2+vendor1-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
389-ds-basesource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2485414

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://bugzilla.redhat.com/show_bug.cgi?id=2485414

OS impact

debian Debian Affected 4 releases
VersionStatusFixed in
trixie Affected —
sid Affected —
bullseye Affected —
bookworm Affected —
suse SUSE Affected 1 release
VersionStatusFixed in
— Affected —

References

CWEs

CWE-416

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.