天下漏洞,尽知其名
HIGH

CVE-2026-103547 OpenBSD ldapd 认证绕过漏洞

影响远程攻击者可绕过认证,以其他身份完成 Bind 登录

AI 研判

OpenBSD 的 ldapd 组件在处理委托 BSD 认证结果时,仅通过 LDAP 子进程的客户端文件描述符和 LDAP 消息 ID 进行关联。当连接关闭后,后续复用相同文件描述符和消息 ID 的连接可能收到先前连接的认证结果,从而以其他身份完成 Bind。此外,连接缺失还可能触发 NULL 指针解引用。

影响范围

OpenBSD ldapd

OpenBSD 7.8(errata 057 之前)与 7.9(errata 021 之前)中的 ldapd。ldapd 默认未启用。

漏洞详情

漏洞类型为认证绕过(含潜在拒绝服务)。成因是 ldapd 对委托 BSD 认证结果的关联标识不唯一,仅依赖文件描述符与消息 ID,二者在连接关闭后可能被复用。攻击者若能访问 ldapd 服务,可构造复用相同描述符与消息 ID 的新连接,窃取先前认证结果,冒充其他身份完成 Bind;连接缺失时还可能引发 NULL 指针解引用。

利用条件与风险

利用前提是目标启用了 ldapd 且攻击者可网络访问该服务,并需满足文件描述符与消息 ID 复用的条件。实战中可导致身份冒用与认证绕过,风险较高;默认未启用降低了整体暴露面。

修复建议

官方修复方案为安装 OpenBSD 7.8 errata 057 或 7.9 errata 021 及之后的勘误补丁。临时缓解措施为在不需要时禁用 ldapd,或限制可访问 ldapd 的网络来源。

原始情报

In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)