CVE-2026-18453
7.5Red Hat · Directory Server
A NULL pointer dereference in 389 Directory Server allows an unauthenticated remote attacker to cause a denial of service by sending crafted LDAP search requests.
Executive summary
A critical denial of service vulnerability in Red Hat Directory Server allows unauthenticated remote attackers to crash the service via crafted LDAP requests.
Vulnerability
This vulnerability is a NULL pointer dereference (CWE-476) occurring within the paged results handling of the op_shared_search function. An unauthenticated attacker can trigger this flaw by submitting a specific sequence of search requests using the USE_ONE_BACKEND control.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a High severity rating due to the ease of exploitation. Successful exploitation results in a denial of service, which can cause significant disruption to identity management and authentication workflows that rely on the Directory Server. This impact could lead to widespread service outages for dependent applications and internal infrastructure.
Remediation
Immediate Action: Update the affected Directory Server packages to the fixed versions identified in the Red Hat errata (RHSA-2026:64771 through RHSA-2026:64784).
Proactive Monitoring: Monitor LDAP server logs for recurring service crashes or an unusual volume of search requests using the USE_ONE_BACKEND control.
Compensating Controls: Implement network-level access controls to restrict LDAP traffic to authorized internal subnets, reducing the exposure of the server to untrusted remote networks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for service disruption and the lack of authentication required to trigger the crash, organizations should prioritize patching affected Red Hat Directory Server instances. Please consult the referenced Red Hat security errata to identify the specific package versions required for your deployment environment and apply these updates immediately to maintain system availability.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Red Hat would like to thank Arthur Chan (Ada Logics) and Team (Anthropic) for reporting this issue., per the CVE Program record.
- RHSA-2026:64771 Vendor advisory
- RHSA-2026:64776 Vendor advisory
- RHSA-2026:64778 Vendor advisory
- RHSA-2026:64779 Vendor advisory
- RHSA-2026:64780 Vendor advisory
- RHSA-2026:64781 Vendor advisory
- RHSA-2026:64783 Vendor advisory
- RHSA-2026:64784 Vendor advisory