Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in 389-ds-base (389 Directory Server). The function get_ldapmessage_controls_ext() in ldap/servers/slapd/control.c parses the optional LDAP v3 Controls field via a decode loop that allocates one LDAPControl struct per control element and grows the pointer list with repeated reallocations, but does not enforce a hard upper bound on the number of controls per message. Under the default nsslapd-maxbersize of 2097152 (2 MB), a remote unauthenticated client can encode hundreds of thousands of minimal non-critical controls in a single LDAP request, forcing attacker-amplified CPU time and heap allocation. The control parsing occurs pre-authentication (e.g., during Bind request processing at bind.c:227), meaning no credentials are required to trigger the vulnerability. Concurrency testing shows that with 4 concurrent 400000-controls Bind requests, heavy requests frequently exceed a 10-second client-side timeout, and independent small probes see latency spikes (baseline p50 ~3ms to stress p50 ~45ms). Sustained pressure can cause worker starvation or OOM termination. This vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), similar in pattern to CVE-2019-10171 in 389-ds-base. Upstream repository: https://github.com/389ds/389-ds-base Callsite: ldap/servers/slapd/control.c, function get_ldapmessage_controls_ext(), line 382-383 Bind entry: ldap/servers/slapd/bind.c, line 227 Confirmed at commit: 761452f79c30bbfd0d6756c4a8ed39549fde5717 Reported by: Oleh Konko of 1seal.org (security) Original report: PSIRTSUPT-6092
Fixed upstream: https://github.com/389ds/389-ds-base/issues/7503
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:26458 https://access.redhat.com/errata/RHSA-2026:26458
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:26452 https://access.redhat.com/errata/RHSA-2026:26452
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:26453 https://access.redhat.com/errata/RHSA-2026:26453
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:26454 https://access.redhat.com/errata/RHSA-2026:26454
This issue has been addressed in the following products: Red Hat Directory Server 11.5 E4S for RHEL 8 Via RHSA-2026:26461 https://access.redhat.com/errata/RHSA-2026:26461
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:26457 https://access.redhat.com/errata/RHSA-2026:26457
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:26460 https://access.redhat.com/errata/RHSA-2026:26460
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26455 https://access.redhat.com/errata/RHSA-2026:26455
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:26464 https://access.redhat.com/errata/RHSA-2026:26464
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:26456 https://access.redhat.com/errata/RHSA-2026:26456
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:26463 https://access.redhat.com/errata/RHSA-2026:26463
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:26459 https://access.redhat.com/errata/RHSA-2026:26459
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:26465 https://access.redhat.com/errata/RHSA-2026:26465
This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:26597 https://access.redhat.com/errata/RHSA-2026:26597
This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:26599 https://access.redhat.com/errata/RHSA-2026:26599
This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:26639 https://access.redhat.com/errata/RHSA-2026:26639