Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86344— 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

Quick assessment

Affected
Red Hat Red Hat Directory Server 11
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 389-ds-base 中发现了一个漏洞。未认证的远程攻击者可以在同一个连接上先发送一个完整的 LDAP 操作,紧接着发送一个不完整的 LDAPMessage 的前几个字节,导致服务器在该第一个工作线程的结果尚未刷出之前,将该连接分配给第二个工作线程。第二个工作线程在持有连接互斥锁的情况下,会阻塞直到 nsslapd-ioblocktimeout 超时时间,从而阻止了已完成操作的结果发送。通过在数量较少(与配置的 Worker 线程池大小成比例)的连接上重复执行上述操作,在默认配置下将耗尽整个线程池,导致所有客

CVSS 7.5 · High EPSS 0.35% · P26

Affected Version Matrix 11

VendorProduct Version RangeStatus
Red Hat Red Hat Directory Server 11 any affected
any affected
Red Hat Red Hat Directory Server 12 any affected
any affected
Red Hat Red Hat Directory Server 13 any affected
Red Hat Red Hat Enterprise Linux 10 any affected
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any unknown
Red Hat Red Hat Enterprise Linux 8 any affected
any affected
Red Hat Red Hat Enterprise Linux 9 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86344

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Directory Server 11 - cpe:/a:redhat:directory_server:11
Red Hat Red Hat Directory Server 11 - cpe:/a:redhat:directory_server:11
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Directory Server 13 - cpe:/a:redhat:directory_server:13
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-86344

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86344

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-86344 (2)

Same Patch Batch · Red Hat · 2026-10-01 · 18 CVEs total

CVE-2026-96658 9.9 CRITICAL Foreman: safemode bypass leading to rce
CVE-2026-96659 9.1 CRITICAL Foreman: excessive permissions for viewer role on preview
CVE-2026-86345 9.0 CRITICAL 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to f
CVE-2026-12405 8.8 HIGH Rubygem-foreman_remote_execution: command injection in job invocations via effective_user
CVE-2026-12541 8.2 HIGH Foreman: command injection in foreman-rake database tasks
CVE-2026-12540 8.2 HIGH Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
CVE-2026-12544 7.7 HIGH Foreman: ssti and insecure deserialization in foreman-rake configuration
CVE-2026-12423 7.5 HIGH Foreman: unauthenticated information disclosure via provisioning token validation flaw
CVE-2026-96577 7.1 HIGH Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a
CVE-2026-12545 6.7 MEDIUM Rubygem-hammer_cli: command injection via insecure editor invocation
CVE-2026-103884 6.5 MEDIUM Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allow
CVE-2026-56097 6.5 MEDIUM Rubygem-katello: sql injection in registry proxy via labels
CVE-2026-83589 6.1 MEDIUM Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
CVE-2026-103754 5.9 MEDIUM Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows
CVE-2026-103641 5.5 MEDIUM Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder
CVE-2026-12542 5.3 MEDIUM Foreman: command injection in foreman-tail
CVE-2026-56098 4.3 MEDIUM Rubygem-katello: improper authorization logic allows resource enumeration

IV. Related Vulnerabilities

V. Comments for CVE-2026-86344

No comments yet


Leave a comment