Impact
A remote, authenticated attacker can send a specially crafted SASL UNBIND request to the 389-ds-base directory service. The malformed request causes the server to stall the connection, leading to resource exhaustion and a denial of service for the affected system. The flaw is a classic example of an out-of-bounds write vulnerability (CWE‑787).
Affected Systems
The vulnerability affects Red Hat Directory Server versions 11, 12, and 13, as well as Red Hat Enterprise Linux operating systems from release 6 through 10. All systems running 389-ds-base on these platforms are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. No EPSS score is available, so the likelihood of exploitation is unknown. The most likely attack vector is remote authenticated LDAP traffic: an attacker must first authenticate to the directory service before sending the malformed UNBIND command. Once exploited, the denial of service lasts for as long as the stalled connections remain open, potentially impacting all clients that rely on the service.
OpenCVE Enrichment