389-ds-base-2.8.0-7.el9_8
エラータID: AXSA:2026-1353:04
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064)
Bug Fix(es) and Enhancement(s):
* Getting "build_candidate_list - Database error 11" messages after migrating to LMDB. [rhel-9.8.z] (JIRA:RHEL-152356)
* Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9.8.z] (JIRA:RHEL-168967)
* DS 12 does not handle escape char in bind user [rhel-9.8.z] (JIRA:RHEL-170269)
* [RFE] Add OS-level thread names to all server threads [rhel-9.8.z] (JIRA:RHEL-174524)
* Online export is failing when using the option "-s" [rhel-9.8.z] (JIRA:RHEL-180716)
* Server shutdown during online reindex may lead to data loss [rhel-9.8.z] (JIRA:RHEL-183895)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-9064
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
Update packages.
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
N/A
SRPMS
- 389-ds-base-2.8.0-7.el9_8.src.rpm
MD5: 3c036b4af881ec058d8c665ba85c9636
SHA-256: 1736c6eb77a0eabe83102499e7bccbe0a99fe10e5d3a53fbce392949caf87820
Size: 48.00 MB
Asianux Server 9 for x86_64
- 389-ds-base-2.8.0-7.el9_8.x86_64.rpm
MD5: 35c44f7b3f419f3d2a2dbb69d6e5c38e
SHA-256: 7979f14ac8c09b21c5e77864627f8e68d2e0e0718bca334fa2046961103f7351
Size: 2.99 MB - 389-ds-base-devel-2.8.0-7.el9_8.x86_64.rpm
MD5: e61ff570f30da63d7a113806ab4b0bbf
SHA-256: 9eef71265b6fbc21e0ff9e13ec4e989ca59438b8c77cee08475e490fb183d010
Size: 126.69 kB - 389-ds-base-libs-2.8.0-7.el9_8.x86_64.rpm
MD5: 9287a0214c1f9b5547ef30780c700eff
SHA-256: 5050e779d5170d33396ee0e18803c2a524ca8383d19d1e29486087185d800096
Size: 1.51 MB - 389-ds-base-snmp-2.8.0-7.el9_8.x86_64.rpm
MD5: da578288d682d6cd195f52255dc96813
SHA-256: e97f402e63e0e50c20dfd6cc58560fdd9303f641d4d7e1e6148920813e583c9c
Size: 48.91 kB - python3-lib389-2.8.0-7.el9_8.noarch.rpm
MD5: 7e5a3723f2f50cebb5795cca081dfafb
SHA-256: db7cca7141d7602d25f1f010cb38f69ec98b59165ccc34676472c8e7ef6f98d0
Size: 1.10 MB