← לוח פגיעויות

CVE-2026-11611

בינונית 6.5

תיאור (מקור, אנגלית)

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-9/8/2026
CWE
CWE-400

מוצרים מושפעים

redhat: directory server; redhat: 389 directory server; redhat: enterprise linux

קישורים