Bug 2485424 (CVE-2026-11611) - CVE-2026-11611 389-ds-base: 389-ds-base: Content Sync plugin unbounded queue growth and race conditions
Summary: CVE-2026-11611 389-ds-base: 389-ds-base: Content Sync plugin unbounded queue ...
Keywords:
Status: NEW
Alias: CVE-2026-11611
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2494775
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-05 12:25 UTC by OSIDB Bzimport
Modified: 2026-07-16 09:10 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-05 12:25:07 UTC
The Content Synchronization (syncrepl) persistent search plugin in 389 Directory Server contains three availability bugs in sync_persist.c:

Bug 1 (primary): Unbounded queue growth — an authenticated user opens a persistent sync search then stops reading responses; modification events queue without limit until memory exhaustion and server crash. Confirmed on UBI 8 and CentOS Stream 8 production binaries (+17MB measured from 500 mods).

Bug 2: sync_persist_terminate() dangling pointer race during connection teardown.

Bug 3: thread_count non-atomic increment/decrement during shutdown (weak memory model architectures).

Vulnerable code present since plugin introduction; no upstream fix as of 2026-04-22.

Comment 1 thierry bordaz 2026-06-08 15:44:05 UTC
Hi @snegrini, would you confirm the due date for this medium (6.5) vulnerability ?


Note You need to log in before you can comment on or make changes to this bug.