389-ds-base: malformed userpassword hash may cause denial of service
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
- BDU:2025-03459
- ALSA-2024:5192
- ALSA-2024:6569
- DLA-4021-1
- openSUSE-SU-2024:14227-1
- RHSA-2024:4633
- RHSA-2024:4997
- RHSA-2024:5192
- RHSA-2024:5690
- RHSA-2024:6153
- RHSA-2024:6568
- RHSA-2024:6569
- RHSA-2024:6576
- RHSA-2024:7458
- RHSA-2025:1632
- RLSA-2024:5192
- RLSA-2024:6569
- SUSE-SU-2024:2910-1
- SUSE-SU-2024:3082-1
- SUSE-SU-2024:3218-1
- Published
- Jun 18, 2024
- Updated
- Jun 17, 2026
- EPSS
- 0.6% · 46th percentile
- CWE
- CWE-1288
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
22
Monitor
Low priority for now.
- CVSS
- 22 / 40 · 5.7 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.6%
CISA SSVC decision
- Exploitation
- none
- Automatable
- no
- Technical impact
- partial
Vulnrichment: CISA's decision-tree inputs.
CNA vs NVD score
- NVD
- —
- CNA · redhat
- 5.7
- NVD has not scored this yet; the score shown is the CNA’s.
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
—
Versions reported by the vendor
Affected version ranges reported by the assigning authority (redhat). Independent of NVD's CPE analysis and usually ahead of it.
github.com/389ds/389-ds-base 389-ds-base
- all versionsaffected
Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8
- 8060020250210084424.0ca98e7e and laternot affected · rpm
Red Hat Red Hat Directory Server 11.7 for RHEL 8
- 8080020240909040333.f969626e and laternot affected · rpm
Red Hat Red Hat Directory Server 11.9 for RHEL 8
- 8100020240902112955.37ed7c03 and laternot affected · rpm
Red Hat Red Hat Directory Server 12.2 EUS for RHEL 9
- 9020020240916150035.1674d574 and laternot affected · rpm
Red Hat Red Hat Directory Server 12.4 for RHEL 9
- 9040020240723122852.1674d574 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 10
- all versionsunknown
Red Hat Red Hat Enterprise Linux 6
- all versionsunknown
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
- 0:1.3.11.1-6.el7_9 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 8
- 8100020240910065753.25e700aa and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support
- 8080020240807050952.6dbb3803 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 9
- 0:2.4.5-9.el9_4 and laternot affected · rpm
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| AlmaLinux:8 | 389-ds-base | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:8 | 389-ds-base-devel | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:8 | 389-ds-base-legacy-tools | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:8 | 389-ds-base-libs | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:8 | 389-ds-base-snmp | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:8 | python3-lib389 | before 1.4.3.39-8.module_el8.10.0+3891+cbd883bf | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf |
| AlmaLinux:9 | 389-ds-base | before 2.4.5-9.el9_4 | 2.4.5-9.el9_4 |
| AlmaLinux:9 | 389-ds-base-devel | before 2.4.5-9.el9_4 | 2.4.5-9.el9_4 |
| AlmaLinux:9 | 389-ds-base-libs | before 2.4.5-9.el9_4 | 2.4.5-9.el9_4 |
| AlmaLinux:9 | python3-lib389 | before 2.4.5-9.el9_4 | 2.4.5-9.el9_4 |
| Debian:11 | 389-ds-base | before 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| Debian:12 | 389-ds-base | before 2.3.1+dfsg1-1+deb12u1 | 2.3.1+dfsg1-1+deb12u1 |
| Debian:13 | 389-ds-base | before 3.1.1+dfsg1-1 | 3.1.1+dfsg1-1 |
| openSUSE:Tumbleweed | 389-ds | before 3.1.1~git0.aef1668-1.1 | 3.1.1~git0.aef1668-1.1 |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-debuginfo | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-debugsource | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-devel | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-legacy-tools | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-legacy-tools-debuginfo | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-libs | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-libs-debuginfo | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-snmp | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
| Red Hat:directory_server_e4s:11.5::el8 | 389-ds-base-snmp-debuginfo | before 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde | 0:1.4.3.34-4.module+el8dsrv+22781+5fe99dde |
+96
Same product
red hat: all recordsOther highest-scoring records for the same primary product.
- CVE-2026-11774389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow30Monitor
- CVE-2024-3657389-ds-base: potential denial of service via specially crafted kerberos as-req request30Monitor
- CVE-2025-14905389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer overflow28Monitor
- CVE-2024-2199389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c22Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| almalinux:389-ds-base | 2.4.5-9.el9_4 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:389-ds-base-devel | 2.4.5-9.el9_4 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:389-ds-base-legacy-tools | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf · AlmaLinux:8 | Package registry (OSV) |
| almalinux:389-ds-base-libs | 2.4.5-9.el9_4 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:389-ds-base-snmp | 1.4.3.39-8.module_el8.10.0+3891+cbd883bf · AlmaLinux:8 | Package registry (OSV) |
| almalinux:python3-lib389 | 2.4.5-9.el9_4 · AlmaLinux:9 | Package registry (OSV) |
| debian:389-ds-base | 2.3.1+dfsg1-1+deb12u1 · Debian:12 | Package registry (OSV) |
| opensuse:389-ds | 2.2.10~git2.345056d3-150600.8.7.2 · openSUSE:Leap 15.6 | Package registry (OSV) |
| red hat:389-ds-base | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:389-ds-base-debuginfo | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:389-ds-base-debugsource | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:389-ds-base-devel | 0:2.4.5-7.module+el9dsrv+22137+7a1133f7 · Red Hat:directory_server:12.4::el9 | Package registry (OSV) |
| red hat:389-ds-base-legacy-tools | 0:1.4.3.35-5.module+el8.8.0+22193+5f98570a · Red Hat:rhel_eus:8.8::appstream | Package registry (OSV) |
| red hat:389-ds-base-legacy-tools-debuginfo | 0:1.4.3.35-5.module+el8.8.0+22193+5f98570a · Red Hat:rhel_eus:8.8::appstream | Package registry (OSV) |
| red hat:389-ds-base-libs | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:389-ds-base-libs-debuginfo | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:389-ds-base-snmp | 0:2.4.5-7.module+el9dsrv+22137+7a1133f7 · Red Hat:directory_server:12.4::el9 | Package registry (OSV) |
| red hat:389-ds-base-snmp-debuginfo | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| red hat:cockpit-389-ds | 0:2.4.5-7.module+el9dsrv+22137+7a1133f7 · Red Hat:directory_server:12.4::el9 | Package registry (OSV) |
| red hat:python3-lib389 | 0:2.2.4-9.el9_2 · Red Hat:rhel_eus:9.2::appstream | Package registry (OSV) |
| rocky linux:389-ds-base | 0:2.4.5-9.el9_4 · Rocky Linux:9 | Package registry (OSV) |
| suse:389-ds | 2.2.10~git2.345056d3-150600.8.7.2 · SUSE:Linux Enterprise Module for Server Applications 15 SP6 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Someone on the same network segment can trigger it.
- A low-privileged account is enough.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- none
- Integrity
- none
- Availability
- high · the service can be disrupted
- Attack vector
- Adjacent
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- High
Weakness class (CWE)
CWE-1288 · Improper Validation of Consistency within InputCVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd-secondary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- access.redhat.com/errata/RHSA-2024:4633
- access.redhat.com/errata/RHSA-2024:4997
- access.redhat.com/errata/RHSA-2024:5192
- access.redhat.com/errata/RHSA-2024:5690
- access.redhat.com/errata/RHSA-2024:6153
- access.redhat.com/errata/RHSA-2024:6568
- access.redhat.com/errata/RHSA-2024:6569
- access.redhat.com/errata/RHSA-2024:6576
- access.redhat.com/errata/RHSA-2024:7458
- access.redhat.com/errata/RHSA-2025:1632
- access.redhat.com/security/cve/CVE-2024-5953
- bugzilla.redhat.com/show_bug.cgi?id=2292104
- lists.debian.org/debian-lts-announce/2025/01/msg00015.html
Vendor advisories and official records. Exploit/PoC links are deliberately left out.