[Pkg-freeipa-devel] Bug#1149732: 389-ds-base: CVE-2026-86344
Salvatore Bonaccorso
carnil at debian.org
Fri Oct 2 19:57:31 BST 2026
Source: 389-ds-base
Version: 3.3.1-3
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security upstream
Hi,
The following vulnerability was published for 389-ds-base.
CVE-2026-86344[0]:
| A flaw was found in 389-ds-base. An unauthenticated remote attacker
| can send a complete LDAP operation followed by the first bytes of an
| incomplete LDAPMessage on the same connection, causing the server to
| hand that connection to a second worker thread before the first
| worker's result is flushed. The second worker blocks until nsslapd-
| ioblocktimeout while holding the connection mutex, preventing
| delivery of the completed operation's result. Repeating this across
| a small number of connections proportional to the configured worker-
| thread pool size exhausts the entire pool under default
| configuration, denying service to all clients (anonymous and
| authenticated, plaintext and TLS) for as long as the attacker
| maintains the connections.
This one is odd, the Red Hat bugzilla entry just contains a hash sum,
which I guess is to identify the internal embargoed tracking? Is this
something tracked/known upstream already?
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-86344
https://www.cve.org/CVERecord?id=CVE-2026-86344
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2529329
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the Pkg-freeipa-devel
mailing list