Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in 389 Directory Server. The op_shared_search function in opshared.c does not check for a NULL backend pointer when reusing a paged-results slot in the be_name (USE_ONE_BACKEND control) code path. An unauthenticated client can exploit this by sending two SEARCH requests on the same connection: the first names a non-existent backend via the USE_ONE_BACKEND control with a Simple Paged Results (SPR) empty cookie, storing NULL as the backend in a paged-results slot; the second names a valid backend with an SPR cookie referencing that slot, causing the server to retrieve the stored NULL and call slapi_be_Rlock(NULL), which dereferences the NULL pointer and crashes the ns-slapd process. This is reachable pre-authentication because control and paged-results processing runs before search authorization. Paged results and anonymous access are both enabled by default.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:64771 https://access.redhat.com/errata/RHSA-2026:64771
This issue has been addressed in the following products: Red Hat Directory Server 12.2 E4S for RHEL 9 Via RHSA-2026:64779 https://access.redhat.com/errata/RHSA-2026:64779
This issue has been addressed in the following products: Red Hat Directory Server 12.4 E4S for RHEL 9 Via RHSA-2026:64780 https://access.redhat.com/errata/RHSA-2026:64780
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:64776 https://access.redhat.com/errata/RHSA-2026:64776
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:64778 https://access.redhat.com/errata/RHSA-2026:64778
This issue has been addressed in the following products: Red Hat Directory Server 11.7 E4S for RHEL 8 Via RHSA-2026:64792 https://access.redhat.com/errata/RHSA-2026:64792
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:64781 https://access.redhat.com/errata/RHSA-2026:64781
This issue has been addressed in the following products: Red Hat Directory Server 11.9 for RHEL 8 Via RHSA-2026:64793 https://access.redhat.com/errata/RHSA-2026:64793
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:64789 https://access.redhat.com/errata/RHSA-2026:64789
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:64790 https://access.redhat.com/errata/RHSA-2026:64790
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:64783 https://access.redhat.com/errata/RHSA-2026:64783
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:64804 https://access.redhat.com/errata/RHSA-2026:64804
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:64791 https://access.redhat.com/errata/RHSA-2026:64791
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:64785 https://access.redhat.com/errata/RHSA-2026:64785
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:64784 https://access.redhat.com/errata/RHSA-2026:64784