Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
Red HatCVE-2026-86344

Red Hat 389-ds-base: resource exhaustion

High7.5CVE-2026-86344 · Published Oct 1, 2026 · updated Oct 2, 2026

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Directory Server 11
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Directory Server 12
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Directory Server 13
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1
Red Hat Satellite 6: command injection
Medium5.3Oct 1
Red Hat Satellite 6: command injection
Medium6.7Oct 1
Red Hat Build of Keycloak: information disclosure
Medium6.5Oct 1
Red Hat Foreman. This vulnerability: information disclosure
Critical9.1Oct 1