Skip to content
Red HatCVE-2026-15041

A flaw was found in 389 Directory Server

Low3.7CVE-2026-15041 · Published Jul 8, 2026 · updated Jul 9, 2026

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Directory Server 11
Product
all versionsNo fix yet
Red Hat Directory Server 12
Product
all versionsNo fix yet
Red Hat Directory Server 13
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-208

More Red Hat advisories

All Red Hat
Advisory
Red Hat, Inc.: CVE records (CNA): denial of service
Medium6.5Jul 8
Red Hat gorch service template: missing authentication
Medium6.3Jul 8
Red Hat TrustyAI Service Operator.: information disclosure
Medium6.3Jul 8
Red Hat Jastow: cross-site scripting
Medium6.5Jul 7
Red Hat GStreamer: incorrect control flow
Low3.7Jul 7
Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted
Medium4.4Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.