389-ds:1.4 security update
エラータID: AXSA:2026-1661:01
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check (CVE-2026-11770)
* 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser (CVE-2026-11788)
* 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing (CVE-2026-15722)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-11770
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
CVE-2026-11788
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
CVE-2026-15722
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
Modularity name: "389-ds"
Stream name: "1.4"
Update packages.
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
N/A
SRPMS
- 389-ds-base-1.4.3.39-26.module+el8+2030+63685bb6.src.rpm
MD5: 205a2517adfa9e58d8462a29c3c5cdea
SHA-256: ae2105bf194e211962491482e89c512c9c01eaed6414885d9557e440ee557f73
Size: 48.61 MB
Asianux Server 8 for x86_64
- 389-ds-base-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: aad4fba8fea31b706ae6707b71b7d4a3
SHA-256: 877f692defd58afe372e616a66a84c31b55ff413ed4fc06734d163cd18157f4b
Size: 3.15 MB - 389-ds-base-debugsource-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: 9b8efaf183a89600119f52460b77b0c5
SHA-256: 211fe2657652a9edb09059d376f6ea4a5e98c97a71ff0dc6ea63a395a98f1894
Size: 2.79 MB - 389-ds-base-devel-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: de20e3c8670b8ce682ab4a7068421996
SHA-256: 6aa74a5ec6e42f72f79169f9db80e9e884edaeb927d440f00ddae740f70c556c
Size: 135.11 kB - 389-ds-base-legacy-tools-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: 461900492472dfeb09a957d0f5dd83d5
SHA-256: 9b1b13cb2b31f3fcc7bddaf4829f70afd3ef2f8d89c06a336ff6e98e36d65adc
Size: 286.73 kB - 389-ds-base-libs-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: c3c2f635da5ee088dfde387428ca6458
SHA-256: 73468cb9f955a955b524e6deecc6e12dfca6c8e80b9c931908031ec7a0959384
Size: 1.52 MB - 389-ds-base-snmp-1.4.3.39-26.module+el8+2030+63685bb6.x86_64.rpm
MD5: 7e0e3382c1c8dc021008c3f392b03d1d
SHA-256: 977f8b84912bf0d0cd6f436b547e41625c512bf9ab533d7dc303e35353d8d4a5
Size: 48.27 kB - python3-lib389-1.4.3.39-26.module+el8+2030+63685bb6.noarch.rpm
MD5: 41178113bbc7bd7a8514a07a9ba57089
SHA-256: c84d1f88b4e137bea460083426d1ebc8f14ec9e9e12a20c778fe4a8f6180e504
Size: 0.98 MB