A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
https://access.redhat.com/errata/RHSA-2026:56050
https://access.redhat.com/errata/RHSA-2026:56048
https://access.redhat.com/errata/RHSA-2026:56047
https://access.redhat.com/errata/RHSA-2026:55794
https://access.redhat.com/errata/RHSA-2026:55758
https://access.redhat.com/errata/RHSA-2026:55757
https://access.redhat.com/errata/RHSA-2026:55756
https://access.redhat.com/errata/RHSA-2026:55532
https://access.redhat.com/errata/RHSA-2026:55530
https://access.redhat.com/errata/RHSA-2026:55426
https://access.redhat.com/errata/RHSA-2026:55425
https://access.redhat.com/errata/RHSA-2026:55424
https://access.redhat.com/errata/RHSA-2026:55423