Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94362.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94362
Upstream
  • CVE-2026-15722
Published
2026-07-31T10:16:44Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-15722 affecting package 389-ds-base 3.1.1-11
Details

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The getruvelementfromberval() function in repl5ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

References

Affected packages

Azure Linux:3 / 389-ds-base

Package

Name
389-ds-base
Purl
pkg:rpm/azure-linux/389-ds-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.1.1-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94362.json"