{"id":"CVE-2026-103547","details":"In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)","modified":"2026-10-03T08:05:11.108927Z","published":"2026-09-30T19:40:53.200Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103547.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.8"},{"fixed":"errata 057"},{"introduced":"7.9"},{"fixed":"errata 021"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"7.8"},{"fixed":"errata 057"},{"introduced":"7.9"},{"fixed":"errata 021"}],"source":"CPE_FIELD"},{"extracted_events":[{"introduced":"7.8"},{"introduced":"7.9"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://ftp.openbsd.org/pub/OpenBSD/patches/7.9/common/021_ldapd.patch.sig"},{"type":"WEB","url":"https://www.openbsd.org/errata78.html"},{"type":"WEB","url":"https://www.openbsd.org/errata79.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103547.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103547"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960"},{"type":"PACKAGE","url":"https://github.com/openbsd/src"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openbsd/src","events":[{"introduced":"0"},{"fixed":"4f3f58e83c2a6d239c544236a9d4d76c74bbf960"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103547.json","vanir_signatures_modified":"2026-10-03T08:05:11Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldape.c","function":"ldape_auth_result"},"deprecated":false,"digest":{"function_hash":"320181844796719245565268040102679801682","length":359},"id":"CVE-2026-103547-02c4949d","signature_type":"Function"},{"id":"CVE-2026-103547-082cec7a","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldapd.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["4575367899496672943996076306877228332","228193375892319665539937103800738175854","315656817447093453822280494934581745109","29690538067379463716791767730309384027","26877821891201321896659482348410397061","305267025796593455350138318543889985417","43410095783276172378125444708063992297","149102886580594548950522619925228707745","330493198626010750519591755247447616627","323719540801453876338323737129538856911","115710380952325168133607464154973877524","181159958522171295836459732130626052256","176876824763256644950074093039494341231","298860794460370627021294731609335592275","44832942702939320218717410511632418025","253891506160177707741639855747408446047","246050585196913208036335764111499226624","270615356913721913716050905845616266113"]}},{"source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldape.c","function":"ldape"},"deprecated":false,"digest":{"length":3808,"function_hash":"89799851279411448102960017581878169870"},"id":"CVE-2026-103547-39d47486","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/conn.c","function":"conn_accept"},"deprecated":false,"digest":{"function_hash":"21943053957834386061829383497960612936","length":1743},"id":"CVE-2026-103547-b9dc9bf6","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"169738983802832864072958422663848242613","length":610},"id":"CVE-2026-103547-c7a69b64","signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldapd.c","function":"ldapd_auth_request"}},{"target":{"file":"usr.sbin/ldapd/conn.c"},"deprecated":false,"digest":{"line_hashes":["285633217489537440337768793372821502092","278884933170155443445545558412553917787","323514573899842161359174588734012220550","319732062636915814651642362492818478880","239734337849849274560989181682867222913","19702056128605642040960292727895939704","233362953054370834079532056018329468440","307689334932061668309481091729902571100","150964502358492124364990639690642597590","69702947143416423399005412033000624688","335526138322613832731088807904133356519","301975941977076258041504189775642122982","234343129558363895123620345039498140327","99516176863920375546142416707355382092","76841972904057868429662664270439263172","2055670220497153451338946235246017918"],"threshold":0.9},"id":"CVE-2026-103547-d432ef14","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960"},{"source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/auth.c","function":"send_auth_request"},"deprecated":false,"digest":{"function_hash":"82734269346400000427231307580532885445","length":623},"id":"CVE-2026-103547-d570bf63","signature_type":"Function","signature_version":"v1"},{"target":{"file":"usr.sbin/ldapd/auth.c"},"deprecated":false,"digest":{"line_hashes":["15232126456328391938896962993229460144","288456785647796751011493905781852232486","131681847687421710357139085630020984100","277750373671556960196899891232431604721","61843754791384510206355981448659524514"],"threshold":0.9},"id":"CVE-2026-103547-e139b5cc","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960"},{"signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldape.c"},"deprecated":false,"digest":{"line_hashes":["23216422264981281420871720523059480450","47089731654168337043584441376598926133","245638367526900575286616695044444335696","10325934358583062551565140112305625198","138020836105763192955731210153673914006","1616364363939847641378135560691372532","300855030468541892088931394528510387273","233431818893682705851441878184384972599","152937516145645745881603703330909623730","46158303951705413814259901099339791654","117800720851821165702881772170288680715"],"threshold":0.9},"id":"CVE-2026-103547-f7078af0","signature_type":"Line"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","target":{"file":"usr.sbin/ldapd/ldapd.c"},"deprecated":false,"digest":{"line_hashes":["87532650969291868748366799042328657940","30426829082885369771249864972982095730","9226818768281750783953446606140573057","48015509500581458992676321034779212095","168827245739722913966192608448304229555"],"threshold":0.9},"id":"CVE-2026-103547-ff3a4dc5"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}