A vulnerability labeled as critical has been found in Red Hat Directory Server and Enterprise Linux. Affected by this issue is the function
get_ldapmessage_controls_ext of the component 389-ds-base. Executing a manipulation can lead to double free.
This vulnerability is tracked as CVE-2026-18663. The attack can be launched remotely. No exploit exists.