Impact
An attacker who can connect to the LDAP service without authentication can send a finished LDAP operation followed by the leading bytes of an unfinished message on the same TCP session. The server mistakenly hands that connection to a second worker thread while the first worker’s response is still being prepared, causing the second thread to block until an i/o timeout expires while holding a mutex. Repeating this pattern on a handful of concurrent connections depletes the entire worker‑thread pool, preventing the server from processing any LDAP requests and effectively shutting it down for all users, whether they are anonymous, authenticated, or connecting over TLS.
Affected Systems
Red Hat Directory Server 11, 12, 13 and Red Hat Enterprise Linux 6, 7, 8, 9, and 10 are affected. The vulnerability exists in the 389‑ds‑base component and its default configuration uses a small worker‑pool size that is susceptible to exhaustion.
Risk and Exploitability
The CVSS score of 7.5 underscores a medium‑high severity DoS risk, and the EPSS score is not available. This flaw is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to open several simultaneous connections from the same source IP, which can be performed over plain or TLS connections without any form of authentication. Once active, the DoS persists as long as the attacker holds the connections; there is no straightforward way for the server to reclaim the exhausted worker threads without interruption.
OpenCVE Enrichment