[ALSA-2026:64784] Critical: 389-ds-base security, bug fix, and enhancement update
Type:
security
Severity:
critical
Release date:
2026-09-10
Description:
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): * 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355) * 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453) * 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922) * 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560) * 389-ds-base: 389-ds-base: CVE-2026-11610 incomplete fix may introduce a connection-stall DoS (CVE-2026-78701) Bug Fix(es) and Enhancement(s): * lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [almalinux-9.8.z] (JIRA:AlmaLinux-244467) * fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [almalinux-9.8.z] (JIRA:AlmaLinux-248766) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 389-ds-base-snmp-2.8.0-10.el9_8.aarch64.rpm 19dc19efbc75b43c11b1386de4b3c3b81ff30b2b821458e81529db9e3ed5c707
aarch64 389-ds-base-2.8.0-10.el9_8.aarch64.rpm 36ee7d4803023e8251b2de8f696471d9350acddc26fc589b0763e1636a7abc37
aarch64 389-ds-base-libs-2.8.0-10.el9_8.aarch64.rpm 8a372c628237bf5692a6845ef3d1254fe5e1071168cec53d698516fe9413eb1b
aarch64 389-ds-base-devel-2.8.0-10.el9_8.aarch64.rpm a147fafa4030a20f9389556c3deaf8038fb2f441c3c3ad1fc00475f2379c3b53
noarch python3-lib389-2.8.0-10.el9_8.noarch.rpm 2f022fe85918e8c3d7805a320a2c2ea198144e5d740733af6dee9815ddf5c6d0
ppc64le 389-ds-base-snmp-2.8.0-10.el9_8.ppc64le.rpm 0fbc81ecdf64c6cd16a9877e0486de200329bf2cf4af10d4bec016c36dede207
ppc64le 389-ds-base-devel-2.8.0-10.el9_8.ppc64le.rpm 7cf3be38fb871970d91991a87d571dfeb4a8ace697aece66b603987e976c93b2
ppc64le 389-ds-base-2.8.0-10.el9_8.ppc64le.rpm 8a100b4973219fa6cba8563f586d07f07eda2d85dc8907b79899d9dfbe3ba33f
ppc64le 389-ds-base-libs-2.8.0-10.el9_8.ppc64le.rpm ca0c87b9dccf87cd3d27a8d55d380a950377b0f9036b6756d57ed3fa9112d7b8
s390x 389-ds-base-devel-2.8.0-10.el9_8.s390x.rpm 1ad23c88cd5436d6d09ebb447f8746bf4d383e81671ec0746421e261f3b5cee0
s390x 389-ds-base-2.8.0-10.el9_8.s390x.rpm 47fd94e90061af8e81416627428cc91320588737374c2c4160c5073096eb0cc7
s390x 389-ds-base-libs-2.8.0-10.el9_8.s390x.rpm 94206a42845a23f6b2ebda48276bee4e6d15a3ac82e9bffa0d5afb62cc24da23
s390x 389-ds-base-snmp-2.8.0-10.el9_8.s390x.rpm d3391cc7c867510adfb1008082da766cc4622fef57682267f71a967c8a172ada
x86_64 389-ds-base-libs-2.8.0-10.el9_8.x86_64.rpm 10b2707f7ee29dff1de00fece5eae2bbcde0d8c23b332a9f207a43b88f176568
x86_64 389-ds-base-2.8.0-10.el9_8.x86_64.rpm 5eaaca7a1996252028ff94307498bfeb15e82286512965c243ea787094cea737
x86_64 389-ds-base-devel-2.8.0-10.el9_8.x86_64.rpm 6a2bed529970f7fad9efdcd9b4a22fc8f499f259724d84f49aed274efe6770b9
x86_64 389-ds-base-snmp-2.8.0-10.el9_8.x86_64.rpm 77a079a6c898321b1eb46e6051da3300df76644022e81195cb3312623660d181
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.