CVE-2026-12528
published 2026-06-17CVE-2026-12528: A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can…
PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.23%
13.2th percentile
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| port389 | 389-ds-base | — | — |
| redhat-ds_11 | 389-ds-base | — | — |
| redhat-ds_12 | 389-ds-base | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
cvelistv5v3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
vendor_redhat5.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
vendor_redhat·2026-06-03·CVSS 5.4
CVE-2026-12528 [LOW] CWE-787 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger h
GHSA
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c.
ghsa_unreviewed·2026-06-17
CVE-2026-12528 [MEDIUM] CWE-787 A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c.
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.
CVEList
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
cvelistv5·2026-06-17·CVSS 5.4
CVE-2026-12528 [MEDIUM] CWE-787 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.
Timeline: 2026-06-03: Reported to Red Hat.; 2026-06-03: Made public.
VulDB
Red Hat Directory Server/Enterprise Linux 389 Directory Server aclparse.c __aclp__normalize_acltxt aci out-of-bounds write
vuldb·2026-06-17
CVE-2026-12528 [CRITICAL] Red Hat Directory Server/Enterprise Linux 389 Directory Server aclparse.c __aclp__normalize_acltxt aci out-of-bounds write
A vulnerability, which was classified as critical, was found in Red Hat Directory Server and Enterprise Linux. The impacted element is the function __aclp__normalize_acltxt of the file aclparse.c of the component 389 Directory Server. Such manipulation of the argument aci leads to out-of-bounds write.
This vulnerability is listed as CVE-2026-12528. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
2026-06-17
Published