Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9064

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

Отчет

This vulnerability is rated Important for Red Hat products shipping 389-ds-base. A remote, unauthenticated attacker with network access to the LDAP port can send a single crafted LDAP request containing an excessive number of minimal controls, causing the server to perform unbounded memory allocations and consume significant CPU time. Under concurrent attack, this can degrade or deny directory service availability through worker thread starvation or out-of-memory conditions. The vulnerability is mitigated in environments where the LDAP port is not exposed to untrusted networks (firewall/ACL restrictions). Additionally, lowering nsslapd-maxbersize reduces the maximum message size (and thus the upper bound on controls per message), though this does not fully eliminate the amplification since it caps bytes rather than control count. The definitive fix requires enforcing a maximum controls-per-message limit in the decode loop.

Меры по смягчению последствий

Restrict network access to the LDAP port (389/tcp, 636/tcp) to trusted networks only using firewall rules or network ACLs. This prevents untrusted remote attackers from reaching the vulnerable code path. Optionally, lower the nsslapd-maxbersize configuration parameter to reduce the maximum BER message size accepted by the server. Note that this caps bytes, not the number of controls, and does not fully eliminate the amplification. Setting it too low may impact legitimate LDAP operations with large payloads.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseWill not fix
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Directory Server 11.5 E4S for RHEL 8redhat-dsFixedRHSA-2026:2646117.06.2026
Red Hat Directory Server 11.7 E4S for RHEL 8redhat-dsFixedRHSA-2026:2659717.06.2026
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:2645817.06.2026
Red Hat Directory Server 12.2 E4S for RHEL 9redhat-dsFixedRHSA-2026:2663917.06.2026
Red Hat Directory Server 12.4 E4S for RHEL 9redhat-dsFixedRHSA-2026:2659917.06.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:2645617.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:2645717.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2480093389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)

EPSS

Процентиль: 53%
0.00815
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
debian
2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...

suse-cvrf
около 1 месяца назад

Security update for 389-ds

suse-cvrf
около 1 месяца назад

Security update for 389-ds

EPSS

Процентиль: 53%
0.00815
Низкий

7.5 High

CVSS3