Количество 16
Количество 16
CVE-2026-9064
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
CVE-2026-9064
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
CVE-2026-9064
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
CVE-2026-9064
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...
openSUSE-SU-2026:21011-1
Security update for 389-ds
SUSE-SU-2026:2419-1
Security update for 389-ds
SUSE-SU-2026:2418-1
Security update for 389-ds
SUSE-SU-2026:2417-1
Security update for 389-ds
SUSE-SU-2026:2316-1
Security update for 389-ds
RLSA-2026:26459
Important: 389-ds:1.4 security update
RLSA-2026:26456
Important: 389-ds-base security, bug fix, and enhancement update
RLSA-2026:26455
Important: 389-ds-base security, bug fix, and enhancement update
GHSA-7r3c-wfgh-x96c
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
ELSA-2026-26459
ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT)
ELSA-2026-26455
ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-26453
ELSA-2026-26453: 389-ds-base security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ... | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21011-1 Security update for 389-ds | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2419-1 Security update for 389-ds | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2418-1 Security update for 389-ds | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2417-1 Security update for 389-ds | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2316-1 Security update for 389-ds | 1% Низкий | около 2 месяцев назад | ||
RLSA-2026:26459 Important: 389-ds:1.4 security update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:26456 Important: 389-ds-base security, bug fix, and enhancement update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:26455 Important: 389-ds-base security, bug fix, and enhancement update | 1% Низкий | около 1 месяца назад | ||
GHSA-7r3c-wfgh-x96c A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
ELSA-2026-26459 ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26455 ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26453 ELSA-2026-26453: 389-ds-base security update (IMPORTANT) | 17 дней назад |
Уязвимостей на страницу