Fedora Account System
Red Hat Associate
Red Hat Customer
The Content Synchronization (syncrepl) persistent search plugin in 389 Directory Server contains three availability bugs in sync_persist.c: Bug 1 (primary): Unbounded queue growth — an authenticated user opens a persistent sync search then stops reading responses; modification events queue without limit until memory exhaustion and server crash. Confirmed on UBI 8 and CentOS Stream 8 production binaries (+17MB measured from 500 mods). Bug 2: sync_persist_terminate() dangling pointer race during connection teardown. Bug 3: thread_count non-atomic increment/decrement during shutdown (weak memory model architectures). Vulnerable code present since plugin introduction; no upstream fix as of 2026-04-22.
Hi @snegrini, would you confirm the due date for this medium (6.5) vulnerability ?