CVE-2026-102731 Apache Directory LDAP API 内存分配过大漏洞
影响攻击者可触发内存耗尽导致拒绝服务
Apache Directory LDAP API 在处理 BER 编码响应时,会依据报文声明的长度值预先分配内存,而未校验该长度是否合理。恶意对端或中间人可发送极小的 BER 报文,诱导客户端分配超大内存,从而引发 OutOfMemoryError 或连接级内存占用,最终导致拒绝服务。
影响范围
Apache Directory LDAP API 1.2.0 至 1.2.9 之前的版本。
漏洞详情
漏洞属于不受控资源消耗(内存分配过大)类型。成因是解码器在收到数据前即按 BER 长度字段分配缓冲区,且 OutOfMemoryError 会绕过 DecoderException 异常处理。攻击者只需发送少量字节即可让客户端 JVM 分配巨量内存,或让每个连接长期占用大块内存并保持停滞。未认证的预绑定客户端即可利用,影响所有未设置 MAX_PDU_SIZE_ATTR 的嵌入服务器。
利用条件与风险
利用无需认证,攻击者或中间人可远程发起;少量连接即可耗尽堆内存,造成服务不可用,实战风险较高。
修复建议
官方建议升级至 1.2.9 版本修复该问题;临时缓解措施可设置 MAX_PDU_SIZE_ATTR 限制最大 PDU 大小,并限制连接数。
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.
A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.
The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.
A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.
This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.
Users are recommended to upgrade to version 1.2.9, which fixes the issue.