CVE-2026-29167
Description
A flaw was found in Apache HTTP Server when using the mod_ldap module in a per-directory configuration. This use-after-free vulnerability allows a remote attacker to potentially execute arbitrary code or cause a denial of service (DoS) due to improper memory handling. This could lead to system instability or unauthorized control over the affected server.
Statement
CISA's 9.8 is a mechanical worst-case UAF score. Their vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — they're treating it as: "network-facing service, memory corruption primitive, assume RCE." This is how CISA-ADP routinely scores any UAF in a network daemon. They don't analyze actual exploitability; they score the theoretical ceiling of the vulnerability class.
Apache's LOW reflects what actually happens.
- Trigger is narrow — mod_ldap must be loaded (not default) AND configured in per-directory context (
, , .htaccess). Server-wide LDAP config doesn't trigger it. This is an unusual configuration pattern. - UAF in config merging, not request handling — the freed memory is in the per-directory configuration merge path, which constrains the timing window and what objects occupy the freed allocation. This isn't a heap spray-friendly UAF in a hot request path.
- httpd's process model kills RCE reliability — prefork uses separate processes (crash = one child dies, parent respawns), worker/event have per-process address space. Turning a UAF into reliable RCE against httpd is substantially harder than against a single-threaded daemon with a predictable heap layout.
- Realistic impact is DoS — the freed pointer will most likely cause a segfault (child crash), not a controlled write primitive. The parent process respawns workers, so even the DoS is transient.
Mitigation
upgrade apache web server to 2.4.68
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.6 | N/A | 9.8 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | Low |
| Privileges Required | Low | N/A | None |
| User Interaction | Required | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | Low | N/A | High |
| Integrity Impact | Low | N/A | High |
| Availability Impact | Low | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.