Executive brief
FreeIPA is an open-source identity management system used by enterprises to manage user accounts, authentication, and authorization across their infrastructure. A flaw in its LDAP enrollment plugin allows an authenticated attacker to crash the directory service by sending a malformed request, causing a denial of service that disrupts identity management operations for all connected systems.
Technical details
A null pointer dereference vulnerability exists in the ipa-enrollment SLAPI plugin that handles LDAP extended operations for host enrollment. An authenticated remote attacker can trigger the crash by omitting the request value for the JOIN_OID parameter in an ipa-enrollment extended operation, causing the server process to crash. The attack requires network-level LDAP access and prior authentication to the directory service. The vulnerability allows only denial of service (application crash); no code execution, data disclosure, or data modification is possible. Patches from Red Hat address this issue in updated FreeIPA packages.
Affected products
- Red Hat FreeIPA <UNKNOWN>
Timeline
- 2026-08-20: disclosed