3.7
CVE-2026-15041
- EPSS 0.3%
- Veröffentlicht 08.07.2026 10:15:30
- Zuletzt bearbeitet 09.07.2026 19:36:15
- Erkennungen
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Directory Server Version 11.0
Redhat ≫ Directory Server Version 12.0
Redhat ≫ Directory Server Version 13.0
Redhat ≫ 389 Directory Server Version -
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.218 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-208 Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
https://access.redhat.com/security/cve/CVE-2026-15041
https://bugzilla.redhat.com/show_bug.cgi?id=2498022