Denial of Service Vulnerability in 389 Directory Server by Red Hat
CVE-2026-11611
6.5MEDIUM
What is CVE-2026-11611?
A vulnerability exists in the 389 Directory Server related to the Content Synchronization persistent search plugin. This flaw allows for unbounded memory growth when an authenticated client fails to read sync responses, ultimately resulting in a denial of service. Furthermore, race conditions in the plugin's thread lifecycle can lead to unexpected crashes during connection teardown or server shutdown. Organizations using affected versions should evaluate their risk and consider implementing mitigations to prevent potential disruption.