In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)
{
"cna_assigner": "mitre",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103547.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.8"
},
{
"fixed": "errata 057"
},
{
"introduced": "7.9"
},
{
"fixed": "errata 021"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "7.8"
},
{
"fixed": "errata 057"
},
{
"introduced": "7.9"
},
{
"fixed": "errata 021"
}
],
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"introduced": "7.8"
},
{
"introduced": "7.9"
}
],
"source": "DESCRIPTION"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103547.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "320181844796719245565268040102679801682",
"length": 359
},
"id": "CVE-2026-103547-02c4949d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldape.c",
"function": "ldape_auth_result"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"4575367899496672943996076306877228332",
"228193375892319665539937103800738175854",
"315656817447093453822280494934581745109",
"29690538067379463716791767730309384027",
"26877821891201321896659482348410397061",
"305267025796593455350138318543889985417",
"43410095783276172378125444708063992297",
"149102886580594548950522619925228707745",
"330493198626010750519591755247447616627",
"323719540801453876338323737129538856911",
"115710380952325168133607464154973877524",
"181159958522171295836459732130626052256",
"176876824763256644950074093039494341231",
"298860794460370627021294731609335592275",
"44832942702939320218717410511632418025",
"253891506160177707741639855747408446047",
"246050585196913208036335764111499226624",
"270615356913721913716050905845616266113"
],
"threshold": 0.9
},
"id": "CVE-2026-103547-082cec7a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldapd.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "89799851279411448102960017581878169870",
"length": 3808
},
"id": "CVE-2026-103547-39d47486",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldape.c",
"function": "ldape"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "21943053957834386061829383497960612936",
"length": 1743
},
"id": "CVE-2026-103547-b9dc9bf6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/conn.c",
"function": "conn_accept"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "169738983802832864072958422663848242613",
"length": 610
},
"id": "CVE-2026-103547-c7a69b64",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldapd.c",
"function": "ldapd_auth_request"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"285633217489537440337768793372821502092",
"278884933170155443445545558412553917787",
"323514573899842161359174588734012220550",
"319732062636915814651642362492818478880",
"239734337849849274560989181682867222913",
"19702056128605642040960292727895939704",
"233362953054370834079532056018329468440",
"307689334932061668309481091729902571100",
"150964502358492124364990639690642597590",
"69702947143416423399005412033000624688",
"335526138322613832731088807904133356519",
"301975941977076258041504189775642122982",
"234343129558363895123620345039498140327",
"99516176863920375546142416707355382092",
"76841972904057868429662664270439263172",
"2055670220497153451338946235246017918"
],
"threshold": 0.9
},
"id": "CVE-2026-103547-d432ef14",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/conn.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "82734269346400000427231307580532885445",
"length": 623
},
"id": "CVE-2026-103547-d570bf63",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/auth.c",
"function": "send_auth_request"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"15232126456328391938896962993229460144",
"288456785647796751011493905781852232486",
"131681847687421710357139085630020984100",
"277750373671556960196899891232431604721",
"61843754791384510206355981448659524514"
],
"threshold": 0.9
},
"id": "CVE-2026-103547-e139b5cc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/auth.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"23216422264981281420871720523059480450",
"47089731654168337043584441376598926133",
"245638367526900575286616695044444335696",
"10325934358583062551565140112305625198",
"138020836105763192955731210153673914006",
"1616364363939847641378135560691372532",
"300855030468541892088931394528510387273",
"233431818893682705851441878184384972599",
"152937516145645745881603703330909623730",
"46158303951705413814259901099339791654",
"117800720851821165702881772170288680715"
],
"threshold": 0.9
},
"id": "CVE-2026-103547-f7078af0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldape.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"87532650969291868748366799042328657940",
"30426829082885369771249864972982095730",
"9226818768281750783953446606140573057",
"48015509500581458992676321034779212095",
"168827245739722913966192608448304229555"
],
"threshold": 0.9
},
"id": "CVE-2026-103547-ff3a4dc5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960",
"target": {
"file": "usr.sbin/ldapd/ldapd.c"
}
}
]
"2026-10-03T08:05:11Z"