CVE-2026-9064
published 2026-05-20CVE-2026-9064: A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.81%
53.3th percentile
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 389-ds_1.4 | 389-ds-base | — | — |
| port389 | 389-ds-base | — | — |
| redhat-ds_11 | 389-ds-base | — | — |
| redhat-ds_12 | 389-ds-base | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
vendor_redhat·2026-05-20·CVSS 7.5
CVE-2026-9064 [HIGH] CWE-770 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
Statement: This vulnerability is rated Important for Red Hat products
GHSA
GHSA-7r3c-wfgh-x96c: A flaw was found in 389-ds-base
ghsa_unreviewed·2026-05-20
CVE-2026-9064 [HIGH] CWE-770 GHSA-7r3c-wfgh-x96c: A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [fedora-all]
bugzilla·2026-05-20·CVSS 7.5
CVE-2026-9064 [HIGH] CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [fedora-all]
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
bugzilla·2026-05-20·CVSS 7.5
CVE-2026-9064 [HIGH] CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
A vulnerability was found in 389-ds-base (389 Directory Server). The function get_ldapmessage_controls_ext() in ldap/servers/slapd/control.c parses the optional LDAP v3 Controls field via a decode loop that allocates one LDAPControl struct per control element and grows the pointer list with repeated reallocations, but does not enforce a hard upper bound on the number of controls per message.
Under the default nsslapd-maxbersize of 2097152 (2 MB), a remote unauthenticated client can encode hundreds of thousands of minimal non-critical controls in a single LDAP request, forcing attacker-amplified CPU time and heap allocation. The control par
https://access.redhat.com/errata/RHSA-2026:26452https://access.redhat.com/errata/RHSA-2026:26453https://access.redhat.com/errata/RHSA-2026:26454https://access.redhat.com/errata/RHSA-2026:26455https://access.redhat.com/errata/RHSA-2026:26456https://access.redhat.com/errata/RHSA-2026:26457https://access.redhat.com/errata/RHSA-2026:26458https://access.redhat.com/errata/RHSA-2026:26459https://access.redhat.com/errata/RHSA-2026:26460https://access.redhat.com/errata/RHSA-2026:26461https://access.redhat.com/errata/RHSA-2026:26463https://access.redhat.com/errata/RHSA-2026:26464https://access.redhat.com/errata/RHSA-2026:26465https://access.redhat.com/errata/RHSA-2026:26597https://access.redhat.com/errata/RHSA-2026:26599https://access.redhat.com/errata/RHSA-2026:26639https://access.redhat.com/errata/RHSA-2026:27125https://access.redhat.com/security/cve/CVE-2026-9064https://bugzilla.redhat.com/show_bug.cgi?id=2480093https://access.redhat.com/errata/RHSA-2026:26452https://access.redhat.com/errata/RHSA-2026:26453https://access.redhat.com/errata/RHSA-2026:26454https://access.redhat.com/errata/RHSA-2026:26455https://access.redhat.com/errata/RHSA-2026:26456https://access.redhat.com/errata/RHSA-2026:26457https://access.redhat.com/errata/RHSA-2026:26458https://access.redhat.com/errata/RHSA-2026:26459https://access.redhat.com/errata/RHSA-2026:26460https://access.redhat.com/errata/RHSA-2026:26461https://access.redhat.com/errata/RHSA-2026:26463https://access.redhat.com/errata/RHSA-2026:26464https://access.redhat.com/errata/RHSA-2026:26465https://access.redhat.com/errata/RHSA-2026:26597https://access.redhat.com/errata/RHSA-2026:26599https://access.redhat.com/errata/RHSA-2026:26639https://access.redhat.com/errata/RHSA-2026:27125https://access.redhat.com/security/cve/CVE-2026-9064https://bugzilla.redhat.com/show_bug.cgi?id=2480093https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9064.json
2026-05-20
Published