PT-2026-47775 · Red Hat · Red Hat Directory Server 11+7

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-11785

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

CVE-2026-11785

Affected Products

Red Hat Directory Server 11
Red Hat Directory Server 12
Red Hat Directory Server 13
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9