A Recycled File Descriptor: CVE-2026-103547 in OpenBSD's ldapd
OpenBSD ldapd CVE-2026-103547 let a remote client inherit another connection's LDAP Bind via a recycled file descriptor.
CVE-2026-103547 is an authentication-confusion flaw in OpenBSD ldapd, scored CVSS 4.0 9.2. The LDAP engine matched BSD authentication results using a client socket file descriptor and message ID, but the kernel can reuse that descriptor after disconnect, so a remote client could finish a Bind as another identity. The same unchecked lookup can NULL-dereference and crash the LDAP engine. ldapd is not enabled by default; fixes in errata 057 (7.8) and 021 (7.9) replace the descriptor with a monotonic connection ID. Franz Bettag of Bettag Systems reported it.