Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12528

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.

Отчет

This flaw in 389 Directory Server has a Low impact. A heap buffer overflow in the ACI parsing function can be triggered by a specially crafted Access Control Instruction (ACI) string. While modern Red Hat Directory Server configurations typically limit write access to the aci attribute to the Directory Manager, certain older deployments or custom ACI patterns could allow other authenticated users to introduce the malformed string. The resulting 1-byte heap corruption is silent in production builds and is not considered weaponizable for code execution.

Меры по смягчению последствий

Ensure that only highly privileged accounts (Directory Manager or explicitly delegated ACI administrators) have write access to the 'aci' attribute. Review existing ACIs for overly broad targetattr rules (especially negated rules like targetattr!="..." or wildcards like targetattr="*") that may inadvertently grant regular users write access to operational attributes including 'aci'. The 389 DS ACI linting tool (lib389) can help identify such misconfigurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseFix deferred
Red Hat Directory Server 12redhat-ds:12/389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2489835389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()

EPSS

Процентиль: 14%
0.00226
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
2 месяца назад

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.

CVSS3: 5.4
nvd
2 месяца назад

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.

CVSS3: 5.4
debian
2 месяца назад

A flaw was found in 389 Directory Server in the __aclp__normalize_aclt ...

CVSS3: 5.4
github
2 месяца назад

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.

suse-cvrf
30 дней назад

Security update for 389-ds

EPSS

Процентиль: 14%
0.00226
Низкий

5.4 Medium

CVSS3