PT-2026-86817 · Opensuse+2 · 389-Ds+29

CVE-2026-18453

·

Publicado

2026-09-07

·

Atualizado

2026-09-10

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op shared search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE ONE BACKEND control, resulting in denial of service.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:64784
CVE-2026-18453
OPENSUSE-SU-2026:11739-1

Produtos afetados

389-Ds
389-Ds-Base
389-Ds-Base-Devel
389-Ds-Base-Libs
389-Ds-Base-Snmp
Red Hat Directory Server 11
Red Hat Directory Server 11.7 E4S For Rhel 8
Red Hat Directory Server 11.9 For Rhel 8
Red Hat Directory Server 12
Red Hat Directory Server 12.2 E4S For Rhel 9
Red Hat Directory Server 12.4 E4S For Rhel 9
Red Hat Directory Server 13
Red Hat Directory Server 13.2
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 10.0 Extended Update Support
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Enterprise Linux 8.8 Update Services For Sap Solutions
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 9.2 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.4 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.6 Extended Update Support
Python3-Lib389