Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Valid heap-buffer-overflow in slapi_dn_normalize_ext() -> sort_rdn_avs() -> rdn_av_swap() (ldap/servers/slapd/dn.c). Triggered when a DN contains a legacy-quoted value encoding a multivalued nested RDN. On closing quote, nested attribute-value tracking is not finalized; a subsequent separator can leave stale pointers that produce overlapping berval entries. In-place sorting then writes past the heap allocation in rdn_av_swap(). Reachable pre-auth via any LDAP operation whose DN is normalized (search base DN confirmed). Reproduced on RHEL 9.8 (389-ds-base-2.8.0-7.el9_8) with reporter PoC. Production behavior (no ASAN/MALLOC_CHECK_): malformed DN often returns err=34 (Invalid DN syntax); server continues. With MALLOC_CHECK_=3: general protection fault in libc, ns-slapd terminates.
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.