Junglewise Threat Intelligence

CVE-2026-12528: 389 Directory Server heap buffer overflow in ACI parsing

CVE-2026-12528 · Severity: medium · CVSS 5.4 · Published 2026-06-17

Technologies: 389ds 389 Directory Server, Red Hat Enterprise Linux. Vendors: Red Hat.

Executive brief

389 Directory Server is an enterprise-grade LDAP server used to manage user identities and access controls. A flaw in how it processes Access Control Instructions (ACIs) allows an authenticated user to corrupt the server's memory by sending a specially crafted instruction. While this could lead to minor data corruption or instability, it typically requires the attacker to already have permissions to modify security settings.

Technical details

A heap-buffer overflow exists in the __aclp__normalize_acltxt() function within aclparse.c of 389 Directory Server. The vulnerability is caused by a failure to validate the length of an Access Control Instruction (ACI) string after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An attacker with network access and LDAP 'write' privileges to the 'aci' attribute can trigger this flaw by submitting a malformed ACI string. While the 1-byte write is not easily weaponized for code execution in production builds, it can lead to silent heap corruption or service instability. A fix has been merged into the upstream main branch.

Affected products

  • 389ds 389 Directory Server 2.x
  • Red Hat Red Hat Directory Server 11, 12, 13
  • Red Hat Red Hat Enterprise Linux 7, 8, 9, 10

Timeline

  • 2026-06-03: patched: Upstream pull request submitted and merged.
  • 2026-06-17: disclosed: Vulnerability disclosed and CVE assigned.
  • 2026-06-17: advisory: Red Hat and NVD published advisory details.

References