389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
Published Oct 1, 2026
7.5
HIGHCVSS 3.1
Description
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Directory Server 11 | affected |
| |||
| Red Hat | Red Hat Directory Server 12 | affected |
| |||
| Red Hat | Red Hat Directory Server 13 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Directory Server 11
389-ds-base
Affected
Red Hat Directory Server 11
redhat-ds:11/389-ds-base
Affected
Red Hat Directory Server 12
389-ds-base
Affected
Red Hat Directory Server 12
redhat-ds:12/389-ds-base
Affected
Red Hat Directory Server 13
389-ds-base
Affected
Red Hat Enterprise Linux 10
389-ds-base
Affected
Red Hat Enterprise Linux 6
389-ds-base
Under investigation
Red Hat Enterprise Linux 7
389-ds-base
Under investigation
Red Hat Enterprise Linux 8
389-ds-base
Affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Affected
Red Hat Enterprise Linux 9
389-ds-base
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Directory Server 11 | 389-ds-base | Affected | n/a |
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Affected | n/a |
| Red Hat Directory Server 12 | 389-ds-base | Affected | n/a |
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | n/a |
| Red Hat Directory Server 13 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 10 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 6 | 389-ds-base | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | 389-ds-base | Under investigation | n/a |
| Red Hat Enterprise Linux 8 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 9 | 389-ds-base | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
As an interim mitigation, administrators can limit the number of concurrent connections permitted per source IP address in front of the LDAP listener (for example via a firewall, load balancer, or a tool such as fail2ban), since exploitation requires several simultaneous connections from the same attacker. Upgrading to a fixed package remains the only complete resolution.
Red Hat statement
This flaw allows an unauthenticated remote attacker to exhaust the entire worker-thread pool of a 389-ds-base LDAP server, denying service to all clients for as long as the attacker maintains a small number of low-cost connections. No authentication, non-default configuration, or privileged access is required to trigger this issue; it is exploitable against the default configuration of the shipped package. There is no risk to the confidentiality or integrity of directory data — no information is disclosed and no data is modified — and the condition is not persistent: normal service resumes within about a second of the attacker releasing its connections, with no restart of the directory server required.
Red Hat mitigation
As an interim mitigation, administrators can limit the number of concurrent connections permitted per source IP address in front of the LDAP listener (for example via a firewall, load balancer, or a tool such as fail2ban), since exploitation requires several simultaneous connections from the same attacker. Upgrading to a fixed package remains the only complete resolution.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (4)
- https://access.redhat.com/security/cve/CVE-2026-86344 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529329 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-86344
- https://www.cve.org/CVERecord?id=CVE-2026-86344
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-86344 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529329 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-86344 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-86344 |
Change history (0)
No recorded changes yet.