CVE-2026-18453
largeUnauthenticated DoS via NULL pointer dereference in 389 Directory Server
389 Directory Server contains a NULL pointer dereference flaw (CWE-476) in the paged-results handling of the op_shared_search function, where a missing NULL check can be hit while processing search operations that carry the USE_ONE_BACKEND control. An unauthenticated remote attacker with network access to the LDAP service can send a crafted sequence of such search requests to drive the server into the faulty code path and crash it. The result is a denial of service: the directory process (ns-slapd) terminates, interrupting LDAP lookups, authentication, and dependent identity services until the service is restarted, with no confidentiality or integrity impact (CVSS 3.1 score 7.5). Any deployment of the affected 389 Directory Server code is in scope, including 389-ds-base distributed by Red Hat (the assigning CNA) with Red Hat Enterprise Linux/Fedora and its role as the directory backend in Red Hat Identity Management/FreeIPA; the source data does not specify exact vulnerable version ranges, so treat currently maintained releases as at-risk pending vendor advisories. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS is 0.8% (percentile 56), so no in-the-wild exploitation has been reported.
What to do: Apply the patched 389-ds-base package from Red Hat/Fedora security advisories as soon as it is available for your release, checking the installed version with 'rpm -q 389-ds-base' on RHEL systems. Until patched, restrict unauthenticated access to LDAP ports 389/636 with firewall or access-control rules, and monitor directory server logs for repeated ns-slapd crashes following bursts of paged search requests.
| Red Hat (389 Directory Server project) 389 Directory Server (389-ds-base) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.