7
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Description
OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer underflow vulnerability in the readline() function. When processing malformed input, an unsigned offset calculation can underflow a heap pointer, resulting in an out-of-bounds read of one byte before the allocated heap buffer. This may allow a local attacker to cause a denial of service and potentially disclose limited heap memory contents.
Basic Information
ID
CVE-2026-22185
Source
VulnCheck
Published
Jan 7, 2026 at 20:26
Modified
Jan 7, 2026 at 21:25
Affected Product
Vendor
OpenLDAP Foundation
Product
OpenLDAP
Affected Versions
OpenLDAP Foundation OpenLDAP 0