389-ds-base-2.8.0-8.el9_8
エラータID: AXSA:2026-1473:05
Release date:
Thursday, August 6, 2026 - 18:03
Subject:
389-ds-base-2.8.0-8.el9_8
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND (CVE-2026-11610)
* 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-11610
CVE-2026-11774
Solution:
Update packages.
CVEs:
CVE-2026-11610
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
CVE-2026-11774
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
Additional Info:
N/A
Download:
SRPMS
- 389-ds-base-2.8.0-8.el9_8.src.rpm
MD5: 7ca5164c22040a132e9c96d145ed9725
SHA-256: 54bb91fde55712e52ea69d45d7078499a73ac837da1e292d575a237e0ce94b8c
Size: 48.00 MB
Asianux Server 9 for x86_64
- 389-ds-base-2.8.0-8.el9_8.x86_64.rpm
MD5: 59db5283885df995561e7f24ccaa9f9c
SHA-256: c576c27dbb11aa719d3d881daf392faca85075af0e44c7cbc429c646df4f4149
Size: 2.99 MB - 389-ds-base-devel-2.8.0-8.el9_8.x86_64.rpm
MD5: 0e3027bf6bf07d8e89ba7f926d2c023f
SHA-256: ce998e0c77ad9eb99c19c1d60f6e58b566792cd56a06ddf21ac9be4f5e6f2811
Size: 127.05 kB - 389-ds-base-libs-2.8.0-8.el9_8.x86_64.rpm
MD5: 746e15a72ad495486e304b3798e69a30
SHA-256: d05ba53e9ebbe3a705db5437cf89dbf7477df1094ad21a093a7caf444aca22e5
Size: 1.51 MB - 389-ds-base-snmp-2.8.0-8.el9_8.x86_64.rpm
MD5: 3c86f9c7e0f1bdecdcfc2af6a975b107
SHA-256: 0f45e3211ab81b0eee78e5c7f50dbb35e8869c682db10b4c238772d451e1ff49
Size: 49.26 kB - python3-lib389-2.8.0-8.el9_8.noarch.rpm
MD5: ac5f964a09abb89842a2e40f0cdcb9f7
SHA-256: cc2ea8add97a92a613c7e5aa9e5841f388035bba819d8e18c2da3715a4f84e2a
Size: 1.10 MB