Skip to content
SUSE 389-ds Denial of Service Vulnerability CVE-2026-9064 Disclosed

SUSE 389-ds Denial of Service Vulnerability CVE-2026-9064 Disclosed

First seen 17 Jun 2026, 03:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 03:02 UTC
  • CVE-2026-9064 affects SUSE 389-ds and can lead to denial of service.
  • The vulnerability allows unbounded LDAP controls, impacting CPU and memory resources.
  • Administrators should apply the released patches immediately to mitigate risks.

SUSE has released updates for the 389-ds directory server to address a critical denial of service vulnerability, CVE-2026-9064. This vulnerability allows unbounded LDAP controls in the `get_ldapmessage_controls_ext()` function, potentially leading to amplified CPU usage and heap allocation issues. Affected systems include SUSE Linux Enterprise Server and various high-performance computing modules. The vulnerability was published on May 20, 2026, and is rated important. The updates are designed to limit the number of controls per operation to mitigate the risk. Administrators are advised to apply the patches immediately to prevent potential service disruptions. The CVSS scores for this vulnerability range from 3.1 to 4.0, indicating a moderate to high risk level. The updates were released on June 16, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-05-20
CVE-2026-9064 published
SUSE disclosed a denial of service vulnerability in the 389-ds directory server affecting multiple SUSE products.
Linuxsecurity
2026-06-16
SUSE releases updates for CVE-2026-9064
Updates were issued to address the denial of service vulnerability in 389-ds, limiting LDAP controls per operation.
Linuxsecurity
2026-06-16
Multiple updates for 389-ds released
SUSE released several updates for different versions of 389-ds to mitigate the same vulnerability.
Linuxsecurity
2026-06-16
Patch for SUSE Linux Enterprise Server issued
An important patch was released for various SUSE Linux Enterprise Server versions to fix CVE-2026-9064.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-9064 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed