Executive brief
A security vulnerability has been identified in the 389 Directory Server, a widely used enterprise-grade directory service. An unauthenticated remote attacker can send a specially crafted request that causes the server to crash or behave unpredictably. This could lead to a denial of service, impacting the availability of authentication and directory services for the organization.
Technical details
A heap-based buffer overflow exists in the slapi_dn_normalize_ext() function within ldap/servers/slapd/dn.c of 389-ds-base. The vulnerability is triggered during the normalization of a Distinguished Name (DN) that contains legacy-quoted values encoding multivalued nested Relative Distinguished Names (RDNs). When sorting RDN attribute-value pairs, the server fails to properly finalize nested tracking, leading to stale pointers and an out-of-bounds write in rdn_av_swap(). An unauthenticated attacker can exploit this by sending an LDAP operation with a crafted base DN, potentially causing a crash (SIGSEGV) or heap corruption. The issue has been reproduced on RHEL 9.8.
Affected products
- 389 Directory Server Project 389-ds-base 2.8.0-7.el9_8 and earlier
- Red Hat Red Hat Directory Server 11, 12, 13
- Red Hat Red Hat Enterprise Linux 7, 8, 9, 10
Timeline
- 2026-07-07: disclosed: Vulnerability reported and published to NVD