← All Advisories

389 Directory Server RUV berval Digit Parser Stack Overflow Reachable Without Credentials

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-15722

Key Details

CVECVE-2026-15722
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
Red HatRed Hat Directory Server 12
Red Hatdirectory_server
Red Hat389_directory_server
Red HatRed Hat Directory Server 11.5 E4S for RHEL 8
Red HatRed Hat Directory Server 11.7 E4S for RHEL 8
Red HatRed Hat Directory Server 11.9 for RHEL 8
Red HatRed Hat Directory Server 12.2 E4S for RHEL 9
Red HatRed Hat Directory Server 12.4 E4S for RHEL 9
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15722
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15722
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-15722