Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18453— 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search

Quick assessment

Affected
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

389 Directory Server 存在一个缺陷。由于 中的分页结果处理缺少对 NULL 指针的检查,未认证的远程攻击者可以通过发送经过构造的、使用 控制项的一系列搜索请求,使 LDAP 服务器崩溃,从而导致拒绝服务(DoS)。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1027 · Obfuscated Files or Information

Affected Version Matrix 8

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18453

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260903102346.f969626e ~ * cpe:/a:redhat:directory_server_e4s:11.7::el8
Red Hat Red Hat Directory Server 11.9 for RHEL 8 8100020260904171440.37ed7c03 ~ * cpe:/a:redhat:directory_server:11.9::el8
Red Hat Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260903155914.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.2::el9
Red Hat Red Hat Directory Server 12.4 E4S for RHEL 9 9040020260903102623.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.4::el9
Red Hat Red Hat Enterprise Linux 10 0:3.2.0-10.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.0.6-21.el10_0 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.3.11.1-15.el7_9 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 8100020260904155442.25e700aa ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020260901171549.96015a92 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 8040020260901171549.96015a92 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 8060020260901145727.824efc52 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 8060020260901145727.824efc52 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 8080020260831180218.6dbb3803 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 8080020260831180218.6dbb3803 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 9 0:2.8.0-10.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.2.4-22.el9_2 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.4.5-29.el9_4 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.6.1-24.el9_6 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Directory Server 13 - cpe:/a:redhat:directory_server:13
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6

II. Public POCs for CVE-2026-18453

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18453

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18453 (2)

Other References for CVE-2026-18453 (15)

Same Patch Batch · Red Hat · 2026-09-07 · 10 CVEs total

CVE-2026-18922 9.8 CRITICAL 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo
CVE-2026-76578 9.8 CRITICAL Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi
CVE-2026-86404 8.8 HIGH Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-
CVE-2026-19843 8.4 HIGH 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console l
CVE-2026-79678 8.1 HIGH Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm
CVE-2026-18355 7.5 HIGH 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound
CVE-2026-76560 7.5 HIGH 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt
CVE-2026-86332 6.5 MEDIUM Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user
CVE-2026-86469 5.3 MEDIUM Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path

IV. Related Vulnerabilities

V. Comments for CVE-2026-18453

No comments yet


Leave a comment