Executive brief
A flaw in 389 Directory Server, a widely-used LDAP directory service, allows an unauthenticated attacker to crash the server by sending specially crafted search requests. An exploitable crash results in denial of service, making the directory service unavailable to legitimate users and potentially disrupting authentication and organizational operations that depend on it.
Technical details
A missing NULL pointer check in the paged results handling of the op_shared_search function allows a NULL pointer dereference. An unauthenticated remote attacker can exploit this by sending a crafted sequence of LDAP search requests that use the USE_ONE_BACKEND control, triggering a crash of the LDAP server process. The vulnerability requires no authentication or user interaction and is reachable over the network. An attacker can achieve denial of service by repeatedly crashing the service. Patches are expected from Red Hat and upstream 389 Project.
Affected products
- 389 Project 389 Directory Server
Timeline
- 2026-09-07: disclosed