Heap Corruption Vulnerability in 389-ds-base by Red Hat
CVE-2026-18663

5.9MEDIUM

What is CVE-2026-18663?

A vulnerability exists in 389-ds-base where the get_ldapmessage_controls_ext() function improperly handles the parsed controls array during critical-control rejection. An unauthenticated attacker can exploit this flaw by sending a crafted BIND request with a specific Session Tracking control, which can lead to a double-free scenario. This results in heap memory corruption, potentially causing denial of service for the affected system.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue.
.