A vulnerability labeled as critical has been found in Red Hat Directory Server and Enterprise Linux . Affected by this issue is the function get_ldapmessage_controls_ext of the component 389-ds-base . Executing a manipulation can lead to double free. This vulnerability is tracked as CVE-2026-18663 . The attack can be launched remotely. No exploit exists.