Impact
The flaw in ldapd causes delegated BSD authentication results to be correlated only by the LDAP child process client file descriptor and message ID. When a connection closes, a subsequent connection that reuses the same file descriptor and message ID can receive the earlier authentication result. Consequently, a remote attacker who can reach the LDAP server can complete a Bind as another identity, gaining unauthorized access. The vulnerability also includes a missing connection check that can lead to a NULL pointer dereference, which may crash ldapd and cause a denial of service.
Affected Systems
OpenBSD OpenBSD versions 7.8 before errata 057 and 7.9 before errata 021 are affected. The fork of ldapd is not enabled by default but may be used in custom configurations.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity vulnerability. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk of exploitation. The likely attack vector is a network attacker able to contact ldapd, which is typically exposed on standard LDAP ports. Once a connection is reopened with the same file descriptor and message ID, the attacker can obtain a valid authentication result for an arbitrary identity, leading to privilege escalation. Administrative privileges or configuration errors that expose ldapd to the network would make exploitation easier.
OpenCVE Enrichment