Impact
An oversized LDAP UNBIND packet can overflow a 512‑byte heap buffer in the SASL I/O layer of the 389 Directory Server after a SASL bind with integrity protection, allowing an authenticated attacker to supply up to approximately 2 MB of attacker‑controlled data; the overflow causes the server to crash, resulting in a denial of service. This flaw has existed since 2013 in the 389‑ds‑base component and was not fixed by earlier patches.
Affected Systems
The vulnerability affects all supported Red Hat Directory Server releases from version 11 through 13, which are available on Red Hat Enterprise Linux 6, 7, 8, 9 and 10. The issue also applies to FreeIPA and Red Hat Identity Management deployments that use Kerberos/GSSAPI authentication, allowing any domain user with a valid Kerberos ticket, any enrolled host or any service account to trigger the crash over the network.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS score of < 1 % suggests a low probability of exploitation at present; the flaw requires access to LDAP ports (389 or 636) over the network and an authenticated SASL session, so the attack vector is an internal or trusted attacker who can obtain SASL credentials. Once the attacker sends a crafted UNBIND packet, the server will crash, impacting availability for the entire directory service. The vulnerability is not listed in KEV.
OpenCVE Enrichment