[Pkg-freeipa-devel] Bug#1149732: 389-ds-base: CVE-2026-86344

Salvatore Bonaccorso carnil at debian.org
Fri Oct 2 19:57:31 BST 2026


Source: 389-ds-base
Version: 3.3.1-3
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for 389-ds-base.

CVE-2026-86344[0]:
| A flaw was found in 389-ds-base. An unauthenticated remote attacker
| can send a complete LDAP operation followed by the first bytes of an
| incomplete LDAPMessage on the same connection, causing the server to
| hand that connection to a second worker thread before the first
| worker's result is flushed. The second worker blocks until nsslapd-
| ioblocktimeout while holding the connection mutex, preventing
| delivery of the completed operation's result. Repeating this across
| a small number of connections proportional to the configured worker-
| thread pool size exhausts the entire pool under default
| configuration, denying service to all clients (anonymous and
| authenticated, plaintext and TLS) for as long as the attacker
| maintains the connections.

This one is odd, the Red Hat bugzilla entry just contains a hash sum,
which I guess is to identify the internal embargoed tracking? Is this
something tracked/known upstream already?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86344
    https://www.cve.org/CVERecord?id=CVE-2026-86344
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2529329

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-freeipa-devel mailing list