Kritická zraniteľnosť Red Hat 389 Directory Server

Vývojári spoločnosti Red Hat opravili kritickú autentifikačnú chybu v komponente 389 Directory Server, ktorá umožňuje neautentifikovanému vzdialenému útočníkovi získať prístup na server s oprávneniami Directory Manager.

Zraniteľné systémy:

  • Red Hat Directory Server 11.7 E4S for RHEL 8
  • Red Hat Directory Server 11.9 for RHEL 8
  • Red Hat Directory Server 12.2 E4S for RHEL 9
  • Red Hat Directory Server 12.4 E4S for RHEL 9
  • Red Hat Enterprise Linux 10
  • Red Hat Enterprise Linux 10.0 Extended Update Support
  • Red Hat Enterprise Linux 6 Extended Lifecycle Support – EXTENSION
  • Red Hat Enterprise Linux 7 Extended Lifecycle Support
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  • Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
  • Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  • Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
  • Red Hat Enterprise Linux 8.8 Telecommunications Update Service
  • Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
  • Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
  • Red Hat Enterprise Linux 9.6 Extended Update Support
  • Red Hat Directory Server 12
  • Red Hat Directory Server 13

Opis činnosti:

CVE-2026-18922 (CVSS skóre 9,8)

Kritická zraniteľnosť v komponente 389 Directory Server v systémoch Red Hat sa nachádza v autentifikačnom mechanizme SASL PLAIN. V procese autentifikácie sa prenáša staršia identita z neúspešného bindu vo vlastnosti Cyrus SASL do následného úspešného bindu.

Vzdialený neautentifikovaný útočník jej zneužitím môže cez pripojenie LDAPS získať oprávnenia na zraniteľnom systéme na úrovni Directory Manager. Na to stačí, keď pošle autentifikačnú požiadavku SASL PLAIN bind s nesprávnym heslom a cn=Directory Manager, a následne dokončiť SASL ANONYMOUS bind v rámci rovnakého pripojenia.

Možné škody:

  • Obídenie bezpečnostných prvkov
  • Eskalácia oprávnení

Odporúčania:

Bezodkladná aktualizácia komponentu 389 Directory Server v systémoch Red Hat podľa pokynov výrobcu.

Odkazy: