CVE-2026-73199

Discovered by AISLEPUBLISHEDCWE-476

Description

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.

CVSS Base Scores

CVSS v3.1(Primary)
6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 10——
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat Enterprise Linux 9——

Credits

  • This issue was discovered by Found by AISLE in partnership with Red Hat.

References