Red Hat Security Advisory: Red Hat Directory Server 13.2 container image update
Red Hat Directory Server is an LDAPv3-compliant directory server. The image is maintained by Red Hat and updated regularly. To pull this container image, run the following command: podman pull registry.redhat.io/dirsrv/dirsrv-container-rhel10:13.2
AI Analysis
Technical Summary
CVE-2026-9064 is a resource exhaustion vulnerability in the get_ldapmessage_controls_ext() function of the 389-ds-base LDAP server used in Red Hat Directory Server. The function does not enforce an upper bound on the number of controls per LDAP message. An attacker can send a crafted LDAP request containing hundreds of thousands of minimal controls within the default 2 MB BER message size, causing excessive CPU usage and heap allocations. Concurrent exploitation can degrade service availability by causing latency, worker thread starvation, or out-of-memory termination, resulting in denial of service. The vulnerability affects Red Hat Directory Server versions 12.2 prior to 12.2.7-15 and 13.2. Mitigations include network access restrictions to LDAP ports and lowering the nsslapd-maxbersize parameter, though only the patch that enforces a maximum controls-per-message limit fully resolves the issue. Red Hat has released an updated container image for version 13.2 containing the fix.
Potential Impact
A remote unauthenticated attacker with network access to the LDAP port can cause denial of service by sending a single crafted LDAP request with an excessive number of controls. This leads to unbounded memory allocations and high CPU consumption, resulting in latency degradation, worker thread starvation, or server termination due to out-of-memory conditions. The impact is availability loss of the directory service. There is no impact on confidentiality or integrity.
Mitigation Recommendations
A patch is available in the updated Red Hat Directory Server 13.2 container image provided by Red Hat. Users should update to this fixed container image by pulling it from the Red Hat container registry. Additionally, network access to LDAP ports (389/tcp and 636/tcp) should be restricted to trusted networks using firewall rules or ACLs to prevent untrusted attackers from reaching the vulnerable code path. Optionally, lowering the nsslapd-maxbersize configuration parameter can reduce the maximum BER message size accepted by the server, partially mitigating the issue, but this does not fully eliminate the amplification and may impact legitimate large LDAP operations.
Red Hat Security Advisory: Red Hat Directory Server 13.2 container image update
Description
Red Hat Directory Server is an LDAPv3-compliant directory server. The image is maintained by Red Hat and updated regularly. To pull this container image, run the following command: podman pull registry.redhat.io/dirsrv/dirsrv-container-rhel10:13.2
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9064 is a resource exhaustion vulnerability in the get_ldapmessage_controls_ext() function of the 389-ds-base LDAP server used in Red Hat Directory Server. The function does not enforce an upper bound on the number of controls per LDAP message. An attacker can send a crafted LDAP request containing hundreds of thousands of minimal controls within the default 2 MB BER message size, causing excessive CPU usage and heap allocations. Concurrent exploitation can degrade service availability by causing latency, worker thread starvation, or out-of-memory termination, resulting in denial of service. The vulnerability affects Red Hat Directory Server versions 12.2 prior to 12.2.7-15 and 13.2. Mitigations include network access restrictions to LDAP ports and lowering the nsslapd-maxbersize parameter, though only the patch that enforces a maximum controls-per-message limit fully resolves the issue. Red Hat has released an updated container image for version 13.2 containing the fix.
Potential Impact
A remote unauthenticated attacker with network access to the LDAP port can cause denial of service by sending a single crafted LDAP request with an excessive number of controls. This leads to unbounded memory allocations and high CPU consumption, resulting in latency degradation, worker thread starvation, or server termination due to out-of-memory conditions. The impact is availability loss of the directory service. There is no impact on confidentiality or integrity.
Mitigation Recommendations
A patch is available in the updated Red Hat Directory Server 13.2 container image provided by Red Hat. Users should update to this fixed container image by pulling it from the Red Hat container registry. Additionally, network access to LDAP ports (389/tcp and 636/tcp) should be restricted to trusted networks using firewall rules or ACLs to prevent untrusted attackers from reaching the vulnerable code path. Optionally, lowering the nsslapd-maxbersize configuration parameter can reduce the maximum BER message size accepted by the server, partially mitigating the issue, but this does not fully eliminate the amplification and may impact legitimate large LDAP operations.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:26639
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a380732eed863c81e00a295
Added to database: 06/21/2026, 15:45:54 UTC
Last enriched: 08/16/2026, 18:22:52 UTC
Last updated: 09/19/2026, 13:46:54 UTC
Views: 142
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.