<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Directory-Services - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/directory-services/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 22:18:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/directory-services/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in 389-ds-base (CVE-2026-86344)</title><link>https://feed.craftedsignal.io/briefs/2026-10-389-ds-base-dos/</link><pubDate>Thu, 01 Oct 2026 22:18:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-389-ds-base-dos/</guid><description>CVE-2026-86344 is a denial-of-service vulnerability in 389-ds-base where an unauthenticated remote attacker can exhaust the server thread pool by sending malformed LDAP messages.</description><content:encoded><![CDATA[<p>CVE-2026-86344 is a critical denial-of-service vulnerability affecting 389-ds-base, a popular LDAP server. An unauthenticated remote attacker can exploit the connection handling logic by sending a complete LDAP operation immediately followed by the initial bytes of an incomplete LDAPMessage on the same connection. This interaction causes a race condition where the server hands the connection to a second worker thread before the first worker flushes its results. The second worker thread then blocks while waiting for the remainder of the incomplete message while holding a connection mutex. By repeating this process across multiple connections, an attacker can exhaust the worker-thread pool, effectively halting service for all clients, including those using plaintext or TLS connections, for the duration of the established connections.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a complete denial of service for the target 389 Directory Server instance. The attack is highly effective as it requires only a small number of connections proportional to the configured worker-thread pool size to cause a total service outage. This impacts any environment relying on 389-ds-base for identity management, authentication, or directory services.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators and security teams:</p>
<ul>
<li>Review 389-ds-base deployment configurations to identify potentially exposed LDAP interfaces.</li>
<li>Implement network-level rate limiting for LDAP traffic (port 389/636) to mitigate the impact of connection-heavy exhaustion attacks.</li>
<li>Monitor logs for unusual patterns of incomplete or malformed LDAP messages if application-level logging is available.</li>
<li>Apply vendor-provided patches for CVE-2026-86344 immediately upon release.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ldap</category><category>authentication-bypass</category><category>directory-services</category></item></channel></rss>