CVE-2026-11791
published 2026-06-18CVE-2026-11791: A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes…
PriorityP426medium5CVSS 3.1
AVNACHPRHUINSUCNILAH
EPSS
0.21%
11.7th percentile
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| port389 | 389-ds-base | — | — |
| redhat-ds_11 | 389-ds-base | — | — |
| redhat-ds_12 | 389-ds-base | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat Directory Server/Enterprise Linux 389 Directory Server attr_syntax_swap_ht use after free
vuldb·2026-06-18
CVE-2026-11791 [CRITICAL] Red Hat Directory Server/Enterprise Linux 389 Directory Server attr_syntax_swap_ht use after free
A vulnerability, which was classified as critical, has been found in Red Hat Directory Server and Enterprise Linux. The impacted element is the function attr_syntax_swap_ht of the component 389 Directory Server. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-11791. The attack is possible to be carried out remotely. No exploit exists.
GHSA
A flaw was found in 389 Directory Server.
ghsa_unreviewed·2026-06-18
CVE-2026-11791 [MEDIUM] CWE-416 A flaw was found in 389 Directory Server.
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).
Red Hat
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
vendor_redhat·2026-04-16·CVSS 5.0
CVE-2026-11791 [MEDIUM] CWE-416 389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
No description is available for this CVE.
Mitigation: Schedule schema reload operations during maintenance windows with reduced LDAP traffic. Minimize schema reload frequency; in replication topologies schema changes propagate automatically. Monitor for unexpected ns-slapd restarts during or immediately after schema reloads. Restrict write access to cn=schema,cn=config to dedicated administrative accounts via LDAP ACIs.
Package: redhat-ds:11/389-ds-base (Red Hat Directory Server 11) - Fix deferred
Package: redhat-ds:12/389-ds-base (Red Hat Directory Server 12) - Fix deferred
Package: 389-ds-base (Red Hat Directory Server 13) - Fix deferred
Package: 389-ds-base (Red Hat Enterprise Linux 10) - Fix defer
No detection rules found.
No public exploits indexed.
2026-06-18
Published