Unknown · 389 Directory Server · CVE-2026-14940
**Name of the Vulnerable Software and Affected Versions**
389 Directory Server (389-ds-base) (affected versions not specified)
**Description**
A heap-buffer-overflow occurs during the normalization of a Distinguished Name (DN) containing a legacy-quoted value that encodes a multivalued nested Relative Distinguished Name (RDN). The server may write past the end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated remote attacker can trigger this by sending an LDAP operation, such as a search with a crafted base DN, that reaches the DN normalization routine. This can lead to heap memory corruption and denial of service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.