CVE-2018-10850: Debian Linux

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject 389 Directory Server: before 1.4.0.10 (fixed in 1.4.0.10)
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.5 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-06-13. Last modified 2026-06-17.