Vulnerability record · CVE-2022-0918 · published 16 March 2022
CVE-2022-0918: Port389 389-ds-base vulnerability
Port389 · 389 Ds Base
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
Description
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0918 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2055815 | Issue TrackingThird Party Advisory |
| https://github.com/389ds/389-ds-base/issues/5242 | Issue TrackingPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | |
| https://access.redhat.com/security/cve/CVE-2022-0918 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2055815 | Issue TrackingThird Party Advisory |
| https://github.com/389ds/389-ds-base/issues/5242 | Issue TrackingPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | |
| https://lists.debian.org/debian-lts-announce/2025/01/msg00015.html |
Track CVE-2022-0918 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0918), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.