Description
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

An attacker who can connect to the LDAP service without authentication can send a finished LDAP operation followed by the leading bytes of an unfinished message on the same TCP session. The server mistakenly hands that connection to a second worker thread while the first worker’s response is still being prepared, causing the second thread to block until an i/o timeout expires while holding a mutex. Repeating this pattern on a handful of concurrent connections depletes the entire worker‑thread pool, preventing the server from processing any LDAP requests and effectively shutting it down for all users, whether they are anonymous, authenticated, or connecting over TLS.

Affected Systems

Red Hat Directory Server 11, 12, 13 and Red Hat Enterprise Linux 6, 7, 8, 9, and 10 are affected. The vulnerability exists in the 389‑ds‑base component and its default configuration uses a small worker‑pool size that is susceptible to exhaustion.

Risk and Exploitability

The CVSS score of 7.5 underscores a medium‑high severity DoS risk, and the EPSS score is not available. This flaw is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to open several simultaneous connections from the same source IP, which can be performed over plain or TLS connections without any form of authentication. Once active, the DoS persists as long as the attacker holds the connections; there is no straightforward way for the server to reclaim the exhausted worker threads without interruption.

Generated by OpenCVE AI on October 1, 2026 at 22:47 UTC.

Remediation

Vendor Workaround

As an interim mitigation, administrators can limit the number of concurrent connections permitted per source IP address in front of the LDAP listener (for example via a firewall, load balancer, or a tool such as fail2ban), since exploitation requires several simultaneous connections from the same attacker. Upgrading to a fixed package remains the only complete resolution.


OpenCVE Recommended Actions

  • Apply the latest Red Hat updates that contain the fix for CVE‑2026‑86344.
  • If an update is unavailable, configure a firewall, load balancer, or fail2ban rule to limit the number of concurrent connections from each source IP to the LDAP listener, as the attack requires multiple simultaneous connections from a single attacker.
  • Consider reducing the worker‑thread pool size or enabling connection‑rate limiting on the LDAP service to lower the impact of a potential exploitation attempt.

Generated by OpenCVE AI on October 1, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Title 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-400
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Directory Server Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T21:29:55.877Z

Reserved: 2026-09-07T09:13:46.693Z

Link: CVE-2026-86344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:05.590

Modified: 2026-10-01T22:17:05.590

Link: CVE-2026-86344

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-01T00:00:00Z

Links: CVE-2026-86344 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:00:20Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption