Описание
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
Отчет
Red Hat rates this issue as Moderate impact. The dereference control plugin in 389-ds-base does not check whether ber_init() succeeded before using the BER structure. If allocation fails, an LDAP search carrying the deref control can crash ns-slapd. The deref plugin is enabled by default, and anonymous clients can send the control when anonymous access is allowed. NVD rates this 7.5 (AC:L); Red Hat rates 5.9 (AC:H) because the NULL return from ber_init() occurs when memory allocation fails, not from a crafted control payload alone—a well-formed deref search on a server with normal free memory does not trigger the crash. Natural OOM was not demonstrated end-to-end without fault injection. Disabling the deref plugin removes the vulnerable code path entirely.
Меры по смягчению последствий
Disable the deref plugin (most effective): dsconf plugin deref disable; systemctl restart dirsrv@. Disable anonymous access (nsslapd-allow-anonymous-access=off) to raise the bar from pre-auth to authenticated exploitation. Configure memory limits as defense-in-depth: set nsslapd-maxbersize and nsslapd-conntablesize, and deploy in a cgroup with memory limits.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | ||
| Red Hat Directory Server 13 | 389-ds-base | Affected | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | ||
| Red Hat Enterprise Linux 7 | 389-ds-base | Affected | ||
| Red Hat Enterprise Linux 8 | 389-ds-base | Affected | ||
| Red Hat Directory Server 11.9 for RHEL 8 | redhat-ds | Fixed | RHSA-2026:55532 | 17.08.2026 |
| Red Hat Enterprise Linux 10 | 389-ds-base | Fixed | RHSA-2026:55424 | 17.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | 389-ds-base | Fixed | RHSA-2026:55425 | 17.08.2026 |
| Red Hat Enterprise Linux 9 | 389-ds-base | Fixed | RHSA-2026:55423 | 17.08.2026 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 389-ds-base | Fixed | RHSA-2026:55421 | 17.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
A flaw was found in 389 Directory Server. The dereference control plug ...
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
EPSS
5.9 Medium
CVSS3