Security finding
Unauthenticated complete LDAP requests can keep every one of the 256 connection slots occupied indefinitely.
Evidence
The server admits sockets before authentication, renews the read deadline before every message, and silently accepts a structurally valid Abandon request without authentication. It has neither a pre-Bind absolute deadline nor a request budget.
Reproduction
Open 256 connections and repeatedly send the valid Abandon PDU:
No Bind or valid JWT is needed. Sending a complete request before each read deadline renews every slot. In the bounded regression, a 500 ms deadline was sustained for more than two deadline periods and the 257th client was closed.
Impact
One permitted network peer can deny fresh authentication at very low request volume. The global cap bounds resource use but provides no fairness between unauthenticated attackers and ClickHouse. The TCP readiness probe can still succeed before an excess connection is closed, so it is not a reliable saturation signal.
Proposed direction
Apply an absolute deadline or small operation budget before first successful Bind. Close or restrict unauthenticated no-op requests, and consider carefully designed per-peer quotas or independently budgeted authenticated connections. Shared ClickHouse source addresses must remain supported.
Validation
Add real-TCP regressions for repeated unauthenticated Abandon, pre-Bind operation limits, successful Bind/Search behavior, and slot reuse.
Security finding
Unauthenticated complete LDAP requests can keep every one of the 256 connection slots occupied indefinitely.
Evidence
The server admits sockets before authentication, renews the read deadline before every message, and silently accepts a structurally valid Abandon request without authentication. It has neither a pre-Bind absolute deadline nor a request budget.
Reproduction
Open 256 connections and repeatedly send the valid Abandon PDU:
No Bind or valid JWT is needed. Sending a complete request before each read deadline renews every slot. In the bounded regression, a 500 ms deadline was sustained for more than two deadline periods and the 257th client was closed.
Impact
One permitted network peer can deny fresh authentication at very low request volume. The global cap bounds resource use but provides no fairness between unauthenticated attackers and ClickHouse. The TCP readiness probe can still succeed before an excess connection is closed, so it is not a reliable saturation signal.
Proposed direction
Apply an absolute deadline or small operation budget before first successful Bind. Close or restrict unauthenticated no-op requests, and consider carefully designed per-peer quotas or independently budgeted authenticated connections. Shared ClickHouse source addresses must remain supported.
Validation
Add real-TCP regressions for repeated unauthenticated Abandon, pre-Bind operation limits, successful Bind/Search behavior, and slot reuse.