Back

HIGH

389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

Published Oct 1, 2026

Description

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.

Affected products

Remediation

Vendor solution

As an interim mitigation, administrators can limit the number of concurrent connections permitted per source IP address in front of the LDAP listener (for example via a firewall, load balancer, or a tool such as fail2ban), since exploitation requires several simultaneous connections from the same attacker. Upgrading to a fixed package remains the only complete resolution.

Red Hat statement

This flaw allows an unauthenticated remote attacker to exhaust the entire worker-thread pool of a 389-ds-base LDAP server, denying service to all clients for as long as the attacker maintains a small number of low-cost connections. No authentication, non-default configuration, or privileged access is required to trigger this issue; it is exploitable against the default configuration of the shipped package. There is no risk to the confidentiality or integrity of directory data — no information is disclosed and no data is modified — and the condition is not persistent: normal service resumes within about a second of the attacker releasing its connections, with no restart of the directory server required.

Red Hat mitigation

As an interim mitigation, administrators can limit the number of concurrent connections permitted per source IP address in front of the LDAP listener (for example via a firewall, load balancer, or a tool such as fail2ban), since exploitation requires several simultaneous connections from the same attacker. Upgrading to a fixed package remains the only complete resolution.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Sep 7, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity Important
Public date Oct 1, 2026