Description
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When
normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a
multivalued nested Relative Distinguished Name (RDN), the server can write past the
end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated
remote attacker can trigger this condition by sending an LDAP operation whose DN
reaches the DN normalization routine, such as a search with a crafted base DN. This
can corrupt heap memory and may cause denial of service.
Published: 2026-07-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑buffer‑overflow flaw exists in the 389 Directory Server when normalizing a Distinguished Name that contains a legacy‑quoted multivalued nested Relative Distinguished Name. The flaw allows the server to write beyond the bounds of a heap allocation while sorting RDN attribute‑value pairs, corrupting heap memory. If triggered, the corruption can lead to a crash or instability of the directory service, resulting in a denial of service.

Affected Systems

Red Hat Directory Server 11, 12, and 13, as well as Red Hat Enterprise Linux 6 through 10 that ship the 389‑ds‑base component, are all affected. Any instance running this component is potentially vulnerable, regardless of the specific operating system variant.

Risk and Exploitability

The attack vector is an unauthenticated remote LDAP operation: an attacker can supply a crafted base DN that triggers the DN normalization routine, such as a search with a specially formatted DN. The CVSS score of 5.3 indicates moderate severity focused on availability, and the EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exposure of the LDAP port to external networks and knowledge of DN formatting are prerequisites for exploitation, which limits but does not eliminate the risk for publicly exposed Directory Server instances.

Generated by OpenCVE AI on July 26, 2026 at 19:25 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat 389‑ds‑base security update that fixes CVE‑2026‑14940 as soon as it becomes available.
  • Restrict LDAP service exposure to trusted networks or VPN tunnels, preventing unauthenticated external access to the directory server.
  • Monitor LDAP logs for abnormal Distinguished Name search patterns and configure alerts for repeated or suspicious operations that may indicate an attempted exploit.

Generated by OpenCVE AI on July 26, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated remote attacker can trigger this condition by sending an LDAP operation whose DN reaches the DN normalization routine, such as a search with a crafted base DN. This can corrupt heap memory and may cause denial of service.
Title 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-122
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Directory Server Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-07T15:35:45.502Z

Reserved: 2026-07-07T12:01:04.779Z

Link: CVE-2026-14940

cve-icon Vulnrichment

Updated: 2026-07-07T15:35:38.356Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-07T12:01:00Z

Links: CVE-2026-14940 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow