Executive brief
389 Directory Server is an enterprise-grade LDAP server used to manage user identities and access controls. A flaw in how it processes Access Control Instructions (ACIs) allows an authenticated user to corrupt the server's memory by sending a specially crafted instruction. While this could lead to minor data corruption or instability, it typically requires the attacker to already have permissions to modify security settings.
Technical details
A heap-buffer overflow exists in the __aclp__normalize_acltxt() function within aclparse.c of 389 Directory Server. The vulnerability is caused by a failure to validate the length of an Access Control Instruction (ACI) string after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An attacker with network access and LDAP 'write' privileges to the 'aci' attribute can trigger this flaw by submitting a malformed ACI string. While the 1-byte write is not easily weaponized for code execution in production builds, it can lead to silent heap corruption or service instability. A fix has been merged into the upstream main branch.
Affected products
- 389ds 389 Directory Server 2.x
- Red Hat Red Hat Directory Server 11, 12, 13
- Red Hat Red Hat Enterprise Linux 7, 8, 9, 10
Timeline
- 2026-06-03: patched: Upstream pull request submitted and merged.
- 2026-06-17: disclosed: Vulnerability disclosed and CVE assigned.
- 2026-06-17: advisory: Red Hat and NVD published advisory details.